Vulnerabilities in langgenius

40 results
Vexday analysis

O fornecedor LangGenius apresenta um panorama moderado de risco com 36 CVEs catalogadas, das quais 3 são críticas (CVSS ≥ 9.0), porém nenhuma está sob exploração ativa conhecida (KEV). A fraqueza dominante é CWE-79 (Cross-site Scripting), sugerindo vulnerabilidades em validação de entrada web. A atividade recente é relevante: 6 vulnerabilidades publicadas nos últimos 90 dias indicam descobertas contínuas que demandam monitoramento e atualização periódica.

CVE-2024-11850MEDIUMStored XSS in langgenius/difyEPSS 0.4%CVE-2025-32796MEDIUMDify Allows Unauthorized APP Enable/Disable via APIEPSS 0.4%CVE-2026-18632MEDIUMlanggenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engineEPSS 0.4%CVE-2026-85022MEDIUMlanggenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scriptingEPSS 0.4%CVE-2026-26023MEDIUMClient‑side DOM XSS in the web chat app of Dify when using echartsEPSS 0.4%CVE-2025-3467HIGHXSS Vulnerability in langgenius/difyEPSS 0.3%CVE-2026-6617MEDIUMlanggenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgeryEPSS 0.3%CVE-2026-6618MEDIUMlanggenius dify ApiBasedToolSchemaParser parser.py parse_openai_plugin_json_to_tool_bundle server-side request forgeryEPSS 0.3%CVE-2025-67732HIGHDify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration EndpointEPSS 0.3%CVE-2025-43862HIGHDify Allows Unauthorized Access and Modification of APP OrchestrationEPSS 0.3%CVE-2026-42138MEDIUMDify Vulnerable to Stored XSS via SVG-file uploadEPSS 0.3%CVE-2026-6619MEDIUMlanggenius dify ImagePreview image-preview.tsx openInNewTab cross site scriptingEPSS 0.3%CVE-2025-32795MEDIUMDify Allows Insecure User Role Access Control for APP EditingEPSS 0.3%CVE-2026-18266MEDIUMDify AI Workflow oauth_redirect_url Open Redirect VulnerabilityEPSS 0.3%CVE-2025-32790MEDIUMDify Allows Insecure User Role Access Control for APP DSL ExportingEPSS 0.3%CVE-2025-49149MEDIUMDify has XSS vulnerabilityEPSS 0.3%CVE-2026-34082MEDIUMDify has IDOR in deleting someone else's chat conversationEPSS 0.3%CVE-2025-59422MEDIUMDify Has Broken Access Control on Log Message Endpoint Allows Reading of Chats of OthersEPSS 0.2%CVE-2025-43854LOWDIFY vulnerable to Clickjacking AttackEPSS 0.2%CVE-2026-21866MEDIUMDify - Stored XSS in chatEPSS 0.2%