216.73.216.197

CVE-2026-42138

· Published 04/05/2026 18:16 · Modified 04/05/2026 20:16

Labels: CVE-2026-42138 2026-05-04CVE-2026-42138CWE-79[email protected]

Essential information

Published
04/05/2026 18:16
Modified
04/05/2026 20:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dify / dify cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:*

References