CVE-2026-26023: Client‑side DOM XSS in the web chat app of Dify when using echarts
Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat frontend when using echarts. User or llm inputs containing echarts containing a specific javascript payload will be executed. This vulnerability is fixed in 1.13.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26023?
CVE-2026-26023 has a medium severity rating due to the potential for client-side DOM XSS exploitation.
How do I fix CVE-2026-26023?
To fix CVE-2026-26023, upgrade to Dify version 1.13.0 or later, where the vulnerability has been addressed.
What component is affected by CVE-2026-26023?
CVE-2026-26023 affects the web chat application of Dify when utilizing echarts.
What type of vulnerability is CVE-2026-26023?
CVE-2026-26023 is classified as a client-side DOM XSS (Cross-Site Scripting) vulnerability.
Who is affected by CVE-2026-26023?
Users running versions prior to 1.13.0 of Dify are affected by CVE-2026-26023.