How TrendAI⢠Research Helped Close an Open Redirect in Dify's Post-Login Flow
ID: 4ee9a46f-f1ee-5adb-b6d9-5c0fa6eefa67
STIX ID: report--4ee9a46f-f1ee-5adb-b6d9-5c0fa6eefa67
Feed Name: TrendAI Security Blog
Threat Score
TrendAI Research discovered an open-redirect vulnerability in Dify's post-login flows (CVE-2026-18266, CVSS 5.4) that allowed freshly authenticated sessions and tokens to be redirected to attacker-controlled origins; TrendAI/ZDI coordinated disclosure and Dify issued a comprehensive fix (centralized redirect-validation and tests) in July 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
