
CVE-2026-42138 Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file… https://www.cve.org/CVERecord?id=CVE-2026-42138
Post summary
The entry announces CVE‑2026‑42138, noting that unauthenticated users can upload SVG files to Dify before v1.13.1, with a link to the CVE record but no PoC, exploit code, or mitigation details.

