{"api_version":"v1","generated_at":"2026-10-06T22:35:00+00:00","product":{"cve_count":27,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-langgenius-dify-e2e5e9dd9afb","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/dify","name":"Dify","next_cursor":null,"observations":[{"affected":"dify: < 1.13.0","affected_versions_present":true,"cve_id":"CVE-2026-105762","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105762","fixed":"1.13.0.","last_modified":"2026-10-05T23:04:58.593Z","patch_url":"https://github.com/langgenius/dify/security/advisories/GHSA-8235-vv5j-mmvg","primary_source":"","published":"2026-10-05T23:04:58.593Z"},{"affected":"dify: < 1.16.0","affected_versions_present":true,"cve_id":"CVE-2026-105761","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-105761","fixed":"1.16.0.","last_modified":"2026-10-05T23:03:44.949Z","patch_url":"https://github.com/langgenius/dify/security/advisories/GHSA-ccrj-frp2-c945","primary_source":"","published":"2026-10-05T23:03:44.949Z"},{"affected":"1.13.0","affected_versions_present":true,"cve_id":"CVE-2026-85022","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85022","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-03T13:25:08.503Z","patch_url":"","primary_source":"","published":"2026-09-03T00:45:14.971Z"},{"affected":"1.13.0","affected_versions_present":true,"cve_id":"CVE-2026-85021","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-85021","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-03T15:01:00.099Z","patch_url":"","primary_source":"","published":"2026-09-03T00:30:10.562Z"},{"affected":"1.14.0; 1.14.1; 1.14.2","affected_versions_present":true,"cve_id":"CVE-2026-18632","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18632","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-03T21:19:13.483Z","patch_url":"","primary_source":"","published":"2026-08-03T19:30:08.375Z"},{"affected":"1.11.4","affected_versions_present":true,"cve_id":"CVE-2026-18266","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-18266","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-29T19:36:20.352Z","patch_url":"","primary_source":"","published":"2026-07-29T19:05:20.221Z"},{"affected":"< 1.16.0-rc1","affected_versions_present":true,"cve_id":"CVE-2026-61461","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-61461","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T22:03:38.857Z","patch_url":"https://github.com/langgenius/dify/pull/38295","primary_source":"","published":"2026-07-10T18:10:35.462Z"},{"affected":"< 1.14.2","affected_versions_present":true,"cve_id":"CVE-2026-41949","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41949","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T20:01:02.231Z","patch_url":"https://github.com/langgenius/dify/pull/35797","primary_source":"","published":"2026-05-18T13:52:03.111Z"},{"affected":"\u2264 1.14.1","affected_versions_present":true,"cve_id":"CVE-2026-41948","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41948","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T20:01:01.518Z","patch_url":"https://github.com/langgenius/dify/pull/35796","primary_source":"","published":"2026-05-18T13:50:21.372Z"},{"affected":"< 1.14.2","affected_versions_present":true,"cve_id":"CVE-2026-41947","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41947","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-07-14T20:01:00.789Z","patch_url":"https://github.com/langgenius/dify/pull/35793","primary_source":"","published":"2026-05-18T13:48:03.568Z"},{"affected":"< 1.14.0","affected_versions_present":true,"cve_id":"CVE-2026-41950","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T20:01:02.893Z","patch_url":"","primary_source":"","published":"2026-05-05T20:35:56.073Z"},{"affected":"< 1.13.1","affected_versions_present":true,"cve_id":"CVE-2026-42138","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-42138","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-04T18:48:58.586Z","patch_url":"","primary_source":"","published":"2026-05-04T17:34:36.199Z"},{"affected":"< 1.13.1","affected_versions_present":true,"cve_id":"CVE-2026-34082","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34082","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-21T13:36:45.614Z","patch_url":"","primary_source":"","published":"2026-04-20T23:03:18.158Z"},{"affected":"1.13.0; 1.13.1; 1.13.2; 1.13.3","affected_versions_present":true,"cve_id":"CVE-2026-6619","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6619","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T13:29:29.634Z","patch_url":"","primary_source":"","published":"2026-04-20T08:00:17.267Z"},{"affected":"1.13.0; 1.13.1; 1.13.2; 1.13.3","affected_versions_present":true,"cve_id":"CVE-2026-6618","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6618","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T16:21:30.799Z","patch_url":"","primary_source":"","published":"2026-04-20T07:45:16.985Z"},{"affected":"0.6.0; 0.6.1; 0.6.2; 0.6.3; 0.6.4; 0.6.5; 0.6.6; 0.6.7","affected_versions_present":true,"cve_id":"CVE-2026-6617","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-6617","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T11:12:15.089Z","patch_url":"","primary_source":"","published":"2026-04-20T07:30:12.357Z"},{"affected":"< 1.11.2","affected_versions_present":true,"cve_id":"CVE-2026-21866","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-21866","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-03-04T21:18:08.260Z","patch_url":"https://github.com/langgenius/dify/pull/29811","primary_source":"","published":"2026-03-03T21:42:25.311Z"},{"affected":"< 1.9.0","affected_versions_present":true,"cve_id":"CVE-2026-28288","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28288","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-27T20:45:44.126Z","patch_url":"","primary_source":"","published":"2026-02-27T20:25:24.599Z"},{"affected":"< 1.13.0","affected_versions_present":true,"cve_id":"CVE-2026-26023","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-26023","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-02-12T21:16:35.748Z","patch_url":"https://github.com/langgenius/dify/commit/378a1d7d08bd0ac5c75eaadc075a0f35211fcb8e","primary_source":"","published":"2026-02-11T21:23:09.866Z"},{"affected":"dify: < 1.11.0","affected_versions_present":true,"cve_id":"CVE-2025-67732","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-67732","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-06T17:39:15.184Z","patch_url":"","primary_source":"","published":"2026-01-05T21:41:01.583Z"},{"affected":"<= 1.9.1","affected_versions_present":true,"cve_id":"CVE-2025-58747","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-58747","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-10-17T15:58:42.220Z","patch_url":"https://github.com/langgenius/dify/commit/bfda4ce7e6f39d43a4420e97e23a18edcfe3e3d3","primary_source":"","published":"2025-10-17T15:48:04.980Z"},{"affected":"= 1.8.1","affected_versions_present":true,"cve_id":"CVE-2025-59422","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59422","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-09-25T15:14:52.506Z","patch_url":"https://github.com/langgenius/dify/commit/b2d8a7eaf1693841411934e2056042845ab4f354","primary_source":"","published":"2025-09-25T13:19:11.385Z"},{"affected":"= 1.2.0","affected_versions_present":true,"cve_id":"CVE-2025-49149","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-49149","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-18T13:39:29.065Z","patch_url":"","primary_source":"","published":"2025-06-17T22:34:24.515Z"},{"affected":"< 1.3.0","affected_versions_present":true,"cve_id":"CVE-2025-43854","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-43854","fixed":"1.3.0.","last_modified":"2025-04-28T18:07:31.146Z","patch_url":"https://github.com/langgenius/dify/pull/18516","primary_source":"","published":"2025-04-28T15:58:54.689Z"},{"affected":"< 0.6.12","affected_versions_present":true,"cve_id":"CVE-2025-43862","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-43862","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-25T15:54:38.110Z","patch_url":"https://github.com/langgenius/dify/pull/5266","primary_source":"","published":"2025-04-25T15:05:32.172Z"},{"affected":"< 0.6.12","affected_versions_present":true,"cve_id":"CVE-2025-32796","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32796","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-18T16:36:51.064Z","patch_url":"https://github.com/langgenius/dify/pull/5266","primary_source":"","published":"2025-04-18T16:06:47.577Z"},{"affected":"< 0.6.12","affected_versions_present":true,"cve_id":"CVE-2025-32795","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32795","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-18T16:37:49.329Z","patch_url":"https://github.com/langgenius/dify/security/advisories/GHSA-gg5w-m2vw-vmmj","primary_source":"","published":"2025-04-18T16:05:11.644Z"},{"affected":"< 0.6.13","affected_versions_present":true,"cve_id":"CVE-2025-32790","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-32790","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-04-18T13:48:27.073Z","patch_url":"https://github.com/langgenius/dify/commit/59ad091e69736bc9dc1a3bace62ec0a232346246","primary_source":"","published":"2025-04-18T12:15:11.487Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"LangGenius"}}
