Vulnerability  ·  2026-07-30

Dify AI Workflow — OAuth Redirect Open Redirect Vulnerability

VulnerabilityLow impactGlobalCVE-2026-18266
NVD published CVE-2026-18266 (CVSS 5.4, Medium) on 2026-07-29, describing an open-redirect vulnerability in Dify's OAuth flow disclosed via Zero Day Initiative.
Dify is a popular open-source LLM app-development platform; while low severity, an open redirect in its OAuth flow could be used in phishing campaigns targeting Dify admins/developers to steal credentials or session tokens.
An attacker crafts a malicious oauth_redirect_url link; when a victim clicks it, they are redirected to an attacker-controlled site, potentially disclosing sensitive OAuth-flow information.
Dify AI Workflow (LangGenius) — oauth_redirect_url parameter
Apply the Dify patch referenced in ZDI-26-452; validate redirect URLs against an allowlist.
NVD CVE-2026-18266Zero Day Initiative Advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →