CVE-2026-85022: langgenius dify WebApp Sign-In mail-and-password-auth.tsx router.replace cross site scripting
A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace of the file web/app/(shareLayout)/webapp-signin/components/mail-and-password-auth.tsx of the component WebApp Sign-In. Such manipulation of the argument redirecturl leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What access and interaction are required for exploitation?
The CVSS vector indicates that an attacker needs low-level privileges and user interaction. The attack can be performed remotely.
Is exploit code available?
Yes. The exploit is publicly available and may be used.
What is known about affected scope?
The reported affected version is langgenius Dify 1.13.0, specifically the WebApp Sign-In component's mail-and-password-auth.tsx handling of the redirect_url argument.