Cross-site scripting in Dify - CVE-2026-21866
Published: July 27, 2026
Dify
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to cross-site scripting in the Mermaid diagram rendering component when rendering Mermaid diagrams within chat conversations. A remote user can create a malicious chat containing a javascript: payload to disclose sensitive information.
User interaction is required to click the generated element in a shared chat.