VYPR

Dify

by Langgenius

Source repositories

CVEs (45)

  • CVE-2025-32795MedApr 18, 2025
    risk 0.00cvss 6.5epss 0.00

    Dify is an open-source LLM app development platform. Prior to version 0.6.12, a vulnerability was identified in the DIFY where normal users are improperly granted permissions to edit APP names, descriptions and icons. This access control flaw allows non-admin users to modify app…

  • CVE-2025-32790MedApr 18, 2025
    risk 0.00cvss 6.3epss 0.00

    Dify is an open-source LLM app development platform. In versions 0.6.8 and prior, a vulnerability was identified in the DIFY AI where normal users are improperly granted permissions to export APP DSL. The feature in '/export' should only allow administrator users to export DSL.…

  • CVE-2025-0184MedMar 20, 2025
    risk 0.00cvss 6.5epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltype value is requested as a URL…

  • CVE-2024-11824HigMar 20, 2025
    risk 0.00cvss 7.6epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like and are not disallowed, allowing an attacker to inject malicious HTML…

  • CVE-2024-10252HigMar 20, 2025
    risk 0.00cvss 7.2epss 0.01

    A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading…

Page 3 of 3