Dismissed
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- speedify
- hiddify-app
- gomodifytags
- haskellPackages.swizzle-modify
- @LeSuisse dismissed
Dify - Stored XSS in chat
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.
References
-
https://github.com/langgenius/dify/security/advisories/GHSA-qpv6-75c2-75h4 x_refsource_CONFIRM
-
https://github.com/langgenius/dify/pull/29811 x_refsource_MISC
Affected products
dify
- ==< 1.11.2
Ignored packages (4)
pkgs.speedify
Use multiple internet connections in parallel
-
nixos-unstable 15.8.2-12611
- nixpkgs-unstable 15.8.2-12611
- nixos-unstable-small 15.8.2-12611
pkgs.hiddify-app
None
pkgs.haskellPackages.swizzle-modify
Swizzle modify functions