Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-10252


A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.


Published

2025-03-20T10:15:15.360

Last Modified

2025-07-11T20:34:47.203

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application langgenius dify ≤ 0.9.1 Yes

References