v3.13.0
LTSUnskippable
Released Sep 29, 2026·Supported until Mar 31, 2028·Community 1.17.1·Community commit e8e5d1e·Enterprise 0.20.0·Helm chart·Docker Compose
Breaking
2 to verify
Security
Issues
Changes
5F · 21B
Downtime
Migration required
Upgrade Impact
Breaking:This release requires an Agent permission migration after upgrading and excludes ChromaDB from the default Enterprise API image. See the Upgrade Guide for upgrade instructions.
RBAC: Agent Permission Migration RequiredMigrates legacy custom role permissions and backfills access records for existing Agents. Until the migration is completed, custom role permissions and access to existing Agents may not work as expected.
API image: ChromaDB excluded from default buildThe default
dify-ee-api image excludes the ChromaDB vector store from this version to address a critical CVE in the ChromaDB dependency. If your deployment relies on ChromaDB, use the docker.io/langgenius/dify-ee-api-insecure:3.13.0 image tag, which includes ChromaDB at the cost of additional known vulnerabilities.CVEs for the opt-in
api-insecure image is excluded from the aggregate counts above.What Changed
28New Features
Multi-Environment DeploymentAdministrators can create environments such as test and prod and configure their resources in the enterprise dashboard. Deploy different published versions of Studio apps to each environment with separate credentials and environment variables. Supports Workflow and Chatflow apps.
Workspace-Level Skills ManagementWorkspaces now support creating, importing, editing, publishing, and versioning reusable Skills containing instructions, scripts, and reference materials. Skills can be used by Agent apps and Agent nodes in workflows, with a built-in Skill Builder, file editor, and granular access controls.
Invocation LogsAdministrators can view app invocation logs across environments in the enterprise dashboard. Inspect the status, duration, token usage, and error details of each invocation to troubleshoot runtime issues.
Agent: Runtime Environment SnapshotsSaves the sandbox environment home directory state during Agent release builds, enabling new sandbox instances running the Agent to reuse pre-packaged dependencies and files.
Plugin Management: Install in Every WorkspaceAdministrators can select "Install in every workspace" for a plugin in the enterprise dashboard. The plugin is installed in existing and newly created workspaces, keeping them on the selected version.
Improvements
RBAC: Granular Agent PermissionsThe single workspace-level agent.manage permission is replaced by agent.create and per-Agent permissions for previewing, editing, testing and running, releasing and managing versions, viewing and managing access points, viewing and managing logs, monitoring, configuring access, importing and exporting DSL, and deleting Agents.
Helm: Per-Site Gateway Response HeadersSupports customizing Gateway HTTP response headers per site via Helm while preserving default header behavior.
Bug Fixes
Admin API RBAC Binding SyncFixed an issue where RBAC permission bindings were not updated when adding or removing workspace members via the Admin API.
Knowledge Base Permission Check 403 ErrorsFixed an issue where 403 errors were incorrectly triggered by legacy permission checks even when knowledge base access was granted.
Workspace Owner Transfer Role SyncFixed an issue where the previous owner role processing and enterprise dashboard display became out of sync after transferring workspace ownership.
SSO Outbound Request Proxy ConfigurationFixed an issue where outbound requests initiated by SSO ignored HTTP_PROXY, HTTPS_PROXY, and NO_PROXY environment variables.
Open in Explore for SSO-Restricted AppsThe Open in Explore action is now hidden for apps restricted to authenticated external users. Previously, this action failed with a misleading "App is not yet published" message.
Web App SAML Authentication Callback RedirectionFixed an issue where completing SAML authentication callbacks in web applications incorrectly redirected users to the console.
SSO: Admin Login with Expired LicensesFixed an issue where expired licenses or exceeded seat limits blocked enterprise dashboard SSO logins, preventing administrators from accessing the system for activation.
Imported Workflow Persistence After PublishingFixed an issue where refreshing the page after successfully publishing an imported workflow caused the workflow to disappear.
Human Input Test Email Modal StatusFixed an issue where opening the test email modal a second time in Human Input nodes falsely displayed the email as sent when it was not.
Prompt Generator: Model Parameter ConfigurationFixed an issue where the prompt generator ignored user-configured model parameters, causing execution errors when using models such as Qwen.
Agent: Duplicate Tool ResultsFixed an issue where tools returning both JSON and text formats caused Agents to receive duplicate results.
User Feedback and Prompt Generation MetricsFixed an issue where metrics related to user feedback and prompt generation were missing from monitoring telemetry.
Workflow Node Execution Metrics and TracingFixed an issue where workflow node execution metrics and trace tracking data were missing.
Unconfigured Tracing Provider HandlingFixed an issue where querying unconfigured providers returned 500 errors when optional tracing SDKs were missing.
Plugin Pod Graceful TerminationFixed an issue where plugin Pods failed to terminate gracefully during shutdown.
Invalid UUID Parameter Response CodeFixed an issue where passing invalid UUID parameters returned a 500 internal server error code instead of 400 bad request.
Pre-installed spaCy Model for Offline Email ExtractionFixed an issue where MSG/email parsing failed in offline environments due to a missing spaCy English model by pre-installing the model in the container image.
Application Deletion Audit LogsFixed an issue where audit log entries were missing during application deletion due to incomplete or missing resource associations.
Helm: Squid Startup Out-of-Memory ErrorsFixed an issue where Squid crashed with out-of-memory errors on startup when host file descriptor limits were set too high, resolved by capping file descriptors via Helm.
Security Notes
Security: setuptools / msgpack CVEs do not affect runtimeThe setuptools and msgpack CVEs flagged by this release's scanner are introduced by dependencies vendored inside the base image's system pip (pip/_vendor). They are not installed in the application virtualenv nor imported by the runtime (which uses uv-managed venvs), so they are not exploitable. The assessment covers four advisories (CVE-2026-57585, GHSA-6v7p-g79w-8964, CVE-2025-47273, CVE-2026-59890); see the VEX (Vulnerability Exploitability eXchange) document linked in the Security & CVE section for the full details.
Security: nltk path-traversal advisory has no upstream fixCVE-2026-81726 (path traversal in
nltk ≤ 3.10.3) is still reported against the API image and has no fixed release upstream. It is the only high-severity finding in the default dify-ee-api image that is not covered by the VEX document; we are tracking the upstream fix and will ship it as soon as one is published.Upgrade Guide
Pre-Upgrade Checklist
Back up PostgreSQL database and Redis data
If your deployment uses ChromaDB, review the known vulnerabilities before selecting the dify-ee-api-insecure:3.13.0 image
Confirm Kubernetes cluster has sufficient resources for rolling update
Schedule a maintenance window; after upgrading, run
flask rbac-migrate-agent-permissions (dry run by default), then rerun with --apply (see Migration Notes)Review the migration requirements of earlier releases when upgrading across multiple versions
Upgrade Command
# Back up database first, then:
$ helm upgrade -i dify -f values.yaml dify-ee/dify --version 3.13.0
Rollback
$ helm rollback dify 0
Security & CVE
Security vulnerabilities found in this release.0 Critical · 28 High CVE across all container images
Image
critical
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
low
4
5
5
4
9
5
5
6
0
6
4
4
4
5
6
4
8
5
5
4
5
0
Status
FAIL
FAIL
PASS
FAIL
FAIL
PASS
PASS
PASS
PASS
PASS
FAIL
FAIL
FAIL
PASS
PASS
PASS
FAIL
PASS
PASS
PASS
FAIL
PASS
ScannerDocker Scout
Scanned
Sep 29, 2026
Data Source
Docker
CVEs for the opt-in
api-insecure image is excluded from the CVE table above.VEX (Vulnerability Exploitability eXchange) documents record why the flagged CVEs are not exploitable in Dify Enterprise.
Benchmark Report
TTFE – Time To First Event (ms)
AVG
412.64
MIN
242
MAX
1441
P50
271
P90
701.1
P95
966.5
Connections
Max Concurrent
3
Avg Active
2.9
Empty Workflow QPS
Max QPS
19.6
Avg QPS
17.63
Avg Duration (ms)
590.45
License Compliance
All dependencies compliant - no copyleft issues detected
Apache-2.0MITBSD-3-ClauseMPL-2.0BSD-2-ClauseISCCC0-1.0