Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Langgenius Dify XSS via redirect_url parameter in Splash Layout

A cross-site scripting vulnerability exists in Langgenius Dify 1.13.0 in the Splash Layout component where the redirect_url parameter is not properly sanitized, allowing remote attackers to execute arbitrary JavaScript code.

Disclosed 3 September 2026 · Record updated 13 September 2026

Impact

Cross-site scripting vulnerability allowing remote code execution via manipulated redirect_url parameter

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-mf5r-rpc2-6jqp