CVE-2026-61461: Dify
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database.
Affected products
- Dify Dify: before 1.16.0 (fixed in 1.16.0)
Published 2026-07-10. Last modified 2026-10-08.