CVE-2024-10252
Last modified
CVE-2024-10252 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Langgenius | Dify | <= 0.9.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-10252?
How severe is CVE-2024-10252?
How do I fix CVE-2024-10252?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-10245The Relais 2FA plugin for WordPress is vulnerable to authent…9.8
- CVE-2024-10246Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-10247The Video Gallery – Best WordPress YouTube Gallery Plugin pl…4.9
- CVE-2024-10249Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-10250The Nioland theme for WordPress is vulnerable to Reflected C…6.1
- CVE-2024-10251Under specific circumstances, insecure permissions in Ivanti…7.8
- CVE-2024-10253A potential TOCTOU vulnerability was reported in PC Manager,…4.7
- CVE-2024-10254A potential buffer overflow vulnerability was reported in PC…4.7
- CVE-2024-10256Insufficient permissions in Ivanti Patch SDK before version …7.1
- CVE-2024-1026A vulnerability was found in Cogites eReserv 7.7.58 and clas…6.1
- CVE-2024-10260The Tripetto plugin for WordPress is vulnerable to Stored Cr…6.1
- CVE-2024-10261The The Paid Membership Subscriptions – Effortless Membershi…7.3
Are you affected by CVE-2024-10252?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
