CVE-2026-42138

MEDIUM

Dify Vulnerable to Stored XSS via SVG-file upload

Title source: cna
STIX 2.1

Description

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/langgenius/dify/releases/tag/1.13.1

Scores

CVSS v3 6.1
EPSS 0.0024
EPSS Percentile 14.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
langgenius/dify < 1.13.1 (2 CPE variants)
Published May 04, 2026
Tracked Since May 04, 2026