langgenius/dify
- <= 0.9.1
A code injection vulnerability has been identified in Langgenius Dify versions through v0.9.1. This issue arises from internal Server-Side Request Forgery (SSRF) requests within the Dify sandbox service, allowing attackers to execute arbitrary Python code with root privileges in the sandbox environment. The exploitation of this vulnerability could result in the complete deletion of the sandbox service, causing irreversible damage.
Exploitation of this vulnerability allows for arbitrary code execution with root privileges in the Dify sandbox environment, potentially leading to the complete destruction of the sandbox service.
Users can update to Dify version 0.10.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.