TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI Research publicly disclosed CVE-2026-18266, a post-login redirect flaw rated 5.4 on CVSS, and provided a link for detailed information.
TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI Research disclosed a post‑login redirect flaw in Dify (CVE‑2026‑18266) that permits an attacker to capture signed‑in session tokens via crafted URLs. The report outlines the vulnerability mechanism but does not provide a patch or exploit code.
TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI reports the discovery of CVE-2026-18266, an unfiltered redirect flaw in Dify’s post-login flow that can leak session tokens via a crafted link. No evidence of active exploitation or patching is mentioned.
TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI Research discloses a redirect-based session token theft vulnerability (CVE-2026-18266) in Dify’s post‑login flow, enabling attackers to capture signed‑in sessions; the linked research provides technical details.
TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI Research disclosed a redirect-based session hijacking vulnerability (CVE-2026-18266) in Dify’s post‑login flow that lets attackers capture signed‑in session tokens via crafted links, with no mention of active exploitation, patches, or PoC code.
TrendAI™ Research[verified]@trendai_RSRCHDisclosure
TrendAI research discloses a post‑login redirect flaw in Dify (CVE‑2026‑18266) that allows attackers to hijack session tokens via crafted URLs.
TrendAI™ Research[verified]@trendai_RSRCHPatch
The post details that Dify has addressed an open‑redirect vulnerability (CVE‑2026‑18266) by releasing a patch; users are advised to upgrade to v1.16.0 and review redirect logs, with a link to the research for more information.