CVEs we hold for Langgenius
Records whose assigning authority named Langgenius as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-85022langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scriptinglanggenius dify
CVE-2026-85021langgenius dify Splash Layout splash.tsx router.replace cross site scriptinglanggenius dify
CVE-2026-6619langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scriptinglanggenius dify
CVE-2026-6618langgenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgerylanggenius dify
CVE-2026-6617langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side…langgenius dify
CVE-2026-61461Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_textlanggenius dify
CVE-2026-18632langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template enginelanggenius dify
CVE-2025-67732Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpointlanggenius dify
CVE-2025-59422Dify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of Otherslanggenius dify
CVE-2025-1796Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in…langgenius/dify
CVE-2024-12039Improper Restriction of Excessive Authentication Attempts in langgenius/difylanggenius/dify
40 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.