Security Advisory

CVE-2026-61461

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-10 18:10:35
Last updated 2026-07-14 22:03:38
Assigner VulnCheck
CVSS score 8.7
State PUBLISHED

Description

Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database.