A vulnerability was found in LangGenius Dify 1.11.4 and classified as problematic. Affected is an unknown function of the component AppInitializer. Executing a manipulation can lead to open redirect.
This vulnerability is tracked as CVE-2026-18266. The attack can be launched remotely. No exploit exists.