Vulnerability Description
A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Langgenius | Dify | <= 0.9.1 |
Related Weaknesses (CWE)
References
- https://github.com/langgenius/dify/commit/4ac99ffe0e1c9f4d7c523908e91bbc7739e0a8Patch
- https://huntr.com/bounties/62c6c958-96cb-426c-aebc-c41f06b9d7b0ExploitThird Party Advisory
FAQ
What is CVE-2024-10252?
CVE-2024-10252 is a vulnerability with a CVSS score of 7.2 (HIGH). A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Pytho...
How severe is CVE-2024-10252?
CVE-2024-10252 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10252?
Check the references section above for vendor advisories and patch information. Affected products include: Langgenius Dify.