VYPR
Medium severity4.3NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-11821

CVE-2024-11821

Description

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Langgenius/Dify2 versions
    cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*
    • (no CPE)range: =0.9.1
  • langgenius/langgenius/difyv5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.