logo

How TrendAI™ Research Helped Close an Open Redirect in Dify's Post-Login Flow

ID: 4ee9a46f-f1ee-5adb-b6d9-5c0fa6eefa67

STIX ID: report--4ee9a46f-f1ee-5adb-b6d9-5c0fa6eefa67

Feed Name: TrendAI Security Blog

Threat Score
50/100

Date Published: 2026-07-29

Date Updated: 2026-08-06

...
...

TrendAI Research discovered an open-redirect vulnerability in Dify's post-login flows (CVE-2026-18266, CVSS 5.4) that allowed freshly authenticated sessions and tokens to be redirected to attacker-controlled origins; TrendAI/ZDI coordinated disclosure and Dify issued a comprehensive fix (centralized redirect-validation and tests) in July 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.