VYPR
Unrated severityNVD Advisory· Published Mar 20, 2025· Updated Mar 20, 2025

Privilege Escalation in langgenius/dify

CVE-2024-11821

Description

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Langgenius/Difyllm-fuzzy
    Range: = 0.9.1
  • langgenius/langgenius/difyv5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.