Medium severity4.3NVD Advisory· Published Apr 20, 2026· Updated Apr 23, 2026
CVE-2026-34082
CVE-2026-34082
Description
Dify is an open-source LLM app development platform. Prior to 1.13.1, the method DELETE /console/api/installed-apps/<appId>/conversations/<conversationId> has poor authorization checking and allows any Dify-authenticated user to delete someone else's chat history. Version 1.13.1 patches the issue.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/langgenius/dify/security/advisories/GHSA-fxq3-hh7x-c63pnvdExploitVendor Advisory
- github.com/langgenius/dify/releases/tag/1.13.1nvdRelease Notes
News mentions
0No linked articles in our index yet.