← Back

CVE-2024-10252

nvd nist
Published: Mar 20, 2025Modified: Jun 17, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.

Affected (1)

Products: Langgenius: Dify
1 product
Dify
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.1

References (2)

Timeline

No history available yet.