HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Open Redirect in Dify AI Workflow OAuth Flow Exposes Sensitive Data (CVE‑2026‑XXXX)

A CVSS 5.4 open‑redirect flaw in Dify’s OAuth handling allows attackers to redirect users to malicious sites and disclose application data. The issue highlights the importance of strict redirect‑URL controls for SOC 2 access‑control compliance.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Open Redirect in Dify AI Workflow OAuth Flow Exposes Sensitive Data (CVE‑2026‑XXXX)

What Happened — A medium‑severity open‑redirect flaw (CVSS 5.4) was discovered in Dify’s oauth_redirect_url handling. An attacker can craft a malicious link that, when visited, forces the OAuth flow to redirect to an attacker‑controlled site, allowing disclosure of information in the application’s context. The vendor has published a patch on GitHub.

Why It Matters for Compliance & Audit Readiness

  • Open‑redirects bypass the trust boundaries that SOC 2 Access Control criteria (CC6.1, CC6.2) are designed to protect.
  • The incident demonstrates the need for continuous monitoring of OAuth configurations and evidence that redirect URLs are whitelisted.
  • Mapping this flaw to your SOC 2 control set provides audit‑ready proof that you remediate authentication‑related misconfigurations promptly.

Who Is Affected — SaaS providers and enterprises that embed Dify AI Workflow for internal or customer‑facing applications (primarily the technology/SaaS sector).

Recommended Actions

  • Review all OAuth redirect URLs in your Dify deployments and enforce a strict whitelist.
  • Apply the vendor‑supplied patch immediately; verify the fix with automated regression testing.
  • Document the remediation in your SOC 2 access‑control evidence repository (e.g., change‑control tickets, configuration baselines).

Technical Notes — The vulnerability resides in the AppInitializer component’s OAuth flow. Exploitation requires user interaction (clicking a malicious link). CVE ID: ZDI‑26‑452 / ZDI‑CAN‑29196. CVSS 5.4 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Patch: https://github.com/langgenius/dify/pull/38864. Source: Zero Day Initiative

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-452/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →