CVE-2026-21866Disclosure(dify / dify)

MEDIUMCVSS 5.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch dify dify systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dify

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-03); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
dify

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-03: 2Mentions · 2026-03-04: 1Mentions · 2026-06-22: 1Active Exploitation · 2026-06-22: 1Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-04: 1Technical Details · 2026-06-22: 103-0303-0406-22
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-032
Disclosure2
2026-03-041
Disclosure1
2026-06-221
Active Exploitation1
Full discourse4 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited authorization bypasses in Dify's multi-tenant AI platform to access private conversations across all tenants using only file UUIDs. The flaws (CVE-2026-41949, CVE-2026-21866) demonstrate how weak tenant isolation can turn single compromises into cross-customer data exposure. #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenants

    Post summary

    Attackers have successfully used CVE-2026-41949 and CVE-2026-21866 to bypass authorization in Dify’s multi‑tenant AI platform, enabling cross‑tenant data exposure.

    0001072
    1.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-21866 Stored XSS in Dify LLM Platform via Mermaid Diagram Rendering Prior to 1.11.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21866

    Post summary

    The text discloses a stored XSS vulnerability (CVE-2026-21866) affecting Dify LLM Platform before version 1.11.2 through Mermaid diagram rendering.

    0001067
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21866 Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occu… https://www.cve.org/CVERecord?id=CVE-2026-21866 ----- Traducción: CVE-2026-21866 Dif… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-21866, a stored XSS vulnerability in Dify’s Mermaid diagram rendering, but provides no PoC, exploit, or patch details.

    0000042
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21866 Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occu… https://www.cve.org/CVERecord?id=CVE-2026-21866

    Post summary

    Dify versions before 1.11.2 are vulnerable to a stored XSS flaw via Mermaid diagrams in chats, and the issue is presumably addressed in the 1.11.2 release.

    00000199
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdifydify---

Explore more