by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
4 packages
- speedify
- hiddify-app
- gomodifytags
- haskellPackages.swizzle-modify
- @LeSuisse dismissed
Dify - Stored XSS in chat
Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2.
References
- https://github.com/langgenius/dify/security/advisories/GHSA-qpv6-75c2-75h4 x_refsource_CONFIRM
- https://github.com/langgenius/dify/pull/29811 x_refsource_MISC
- https://github.com/langgenius/dify/commit/ae17537470bba417a8971fff705dd82ecb043564 x_refsource_MISC
Affected products
- ==< 1.11.2
Ignored packages (4)
pkgs.speedify
Use multiple internet connections in parallel
-
nixos-unstable 15.8.2-12611
- nixpkgs-unstable 15.8.2-12611
- nixos-unstable-small 15.8.2-12611
-
nixos-25.11 15.8.2-12611
- nixos-25.11-small 15.8.2-12611
- nixpkgs-25.11-darwin 15.8.2-12611
pkgs.hiddify-app
Multi-platform auto-proxy client, supporting Sing-box, X-ray, TUIC, Hysteria, Reality, Trojan, SSH etc