Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvmg-6fvg-2jp2

Опубликовано: 20 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
nvd
11 месяцев назад

A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.

EPSS

Процентиль: 35%
0.00146
Низкий

8.8 High

CVSS3

Дефекты

CWE-94