Medium severity4.3NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-11821
CVE-2024-11821
Description
A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*+ 1 more
- cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*
- (no CPE)range: =0.9.1
- langgenius/langgenius/difyv5Range: unspecified
Patches
Vulnerability mechanics
References
1- huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.