CVE-2026-85021

Source
https://cve.org/CVERecord?id=CVE-2026-85021
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85021.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-85021
Aliases
  • GHSA-7qgm-pqv4-668x
Published
2026-09-03T00:30:10.562Z
Modified
2026-09-05T03:48:41.304941727Z
Severity
  • 2.1 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
langgenius dify Splash Layout splash.tsx router.replace cross site scripting
Details

A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "cwe_ids": [
        "CWE-79",
        "CWE-94"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/85xxx/CVE-2026-85021.json"
}
References

Affected packages

Git / github.com/langgenius/dify

Affected ranges

Type
GIT
Repo
https://github.com/langgenius/dify
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.13.0"
        },
        {
            "last_affected": "1.13.0"
        }
    ]
}

Affected versions

1.*
1.13.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-85021.json"