
CVE-2026-26023 Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when us… https://www.cve.org/CVERecord?id=CVE-2026-26023
Post summary
CVE-2026-26023 is a cross‑site scripting flaw in Dify's chat frontend affecting versions prior to 1.13.0, with no evidence of active exploitation, available exploits, or patches mentioned.
