Impact
A flaw in langgenius dify version 1.13.0 allows an attacker to manipulate the redirect_url argument passed to the router.replace function in the WebApp Sign‑In module. This manipulation results in cross site scripting that can execute arbitrary JavaScript within the victim’s browser session.
Affected Systems
langgenius dify version 1.13.0
Risk and Exploitability
The CVSS score of 5.1 classifies the vulnerability as moderate severity. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog. The attacker can perform the exploit remotely by sending a crafted redirect_url to the public sign‑in endpoint; exploitation does not require prior authentication or elevated privileges. Publicly available exploit code suggests the flaw is trivial to abuse once a malicious payload is delivered.
OpenCVE Enrichment