VYPR

Dify

by Langgenius

Source repositories

CVEs (43)

  • CVE-2025-0184MedMar 20, 2025
    risk 0.00cvss 6.5epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltype value is requested as a URL…

  • CVE-2024-11824HigMar 20, 2025
    risk 0.00cvss 7.6epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like and are not disallowed, allowing an attacker to inject malicious HTML…

  • CVE-2024-10252HigMar 20, 2025
    risk 0.00cvss 7.2epss 0.01

    A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading…

Page 3 of 3