CVE-2026-42138: Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/...

Added to the CISA Known Exploited Vulnerabilities catalog on 04 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.1.

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This is...

Required action: Review and patch if applicable to your AI infrastructure.