CVE-2026-61461
langgenius dify
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database.
- CVSS
- 8.7
- EPSS
- 0.36% 27.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11