Skip to main content
Loading…
    CVE-2026-42138 — Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/fil — CVE Database · The Intelligence Room