github.com
https://github.com/langgenius/dify/releases/tag/1.13.1 CVE-2026-42138
MEDIUM
Dify Vulnerable to Stored XSS via SVG-file upload
Record summary
CVE-2026-42138 has a selected CVSS score of 6.9 (medium).
Description
Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 4, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | < 1.13.1 | affected |
References
2github.comConfirmation
https://github.com/langgenius/dify/security/advisories/GHSA-cg94-8v83-7hjj