CVE-2026-85021 | langgenius dify 1.13.0 Splash Layout splash.tsx router.replace redirect_url cross site scripting
A vulnerability, which was classified as problematic, has been found in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(shareLayout)/components/splash.tsx of the component Splash Layout. This manipulation of the argument redirect_url causes cross site scripting.
This vulnerability is tracked as CVE-2026-85021. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More