취약점  ·  2026-07-30

Dify AI Workflow — OAuth 리다이렉트 오픈 리다이렉트 취약점

취약점Low 영향도GlobalCVE-2026-18266
NVD는 2026-07-29에 CVE-2026-
Dify is a popular open-source LLM app-development platform; while low severity, an open redirect in its OAuth flow could be used in phishing campaigns targeting Dify admins/developers to steal credentials or session tokens.
An attacker crafts a malicious oauth_redirect_url link; when a victim clicks it, they are redirected to an attacker-controlled site, potentially disclosing sensitive OAuth-flow information.
Dify AI Workflow (LangGenius) — oauth_redirect_url parameter
Apply the Dify patch referenced in ZDI-26-452; validate redirect URLs against an allowlist.
NVD CVE-2026-18266Zero Day Initiative Advisory
라이브 피드에서 보기 AI 보안 및 거버넌스 관련 소식을 더 살펴보세요 — 매일 아침 업데이트.
피드 열기 →