CVE-2026-34082: Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversationId>` has poor authorization checking and allo...
Added to the CISA Known Exploited Vulnerabilities catalog on 20 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.3.
Dify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversationId>` has poor authorization checking and allows any Dify-authenticated user to delete someone else's chat history. Version 1.13.1 patches the issue.
Required action: Review and patch if applicable to your AI infrastructure.