A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.
History

Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.
Title Code Injection in langgenius/dify
Weaknesses CWE-94
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-03-20T10:10:41.847Z

Updated: 2025-03-20T18:18:19.708Z

Reserved: 2024-10-22T16:40:04.945Z

Link: CVE-2024-10252

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-03-20T10:15:15.360

Modified: 2025-03-20T10:15:15.360

Link: CVE-2024-10252

cve-icon Redhat

No data.