Langgenius Dify XSS via redirect_url parameter in Splash Layout
A cross-site scripting vulnerability exists in Langgenius Dify 1.13.0 in the Splash Layout component where the redirect_url parameter is not properly sanitized, allowing remote attackers to execute arbitrary JavaScript code.
Disclosed 3 September 2026 · Record updated 13 September 2026
Impact
Cross-site scripting vulnerability allowing remote code execution via manipulated redirect_url parameter
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-mf5r-rpc2-6jqp
