CVE-2024-11821

A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.
References
Link Resource
https://huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*

History

14 Jul 2025, 17:25

Type Values Removed Values Added
References () https://huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6 - () https://huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6 - Exploit, Third Party Advisory
Summary
  • (es) Existe una vulnerabilidad de escalada de privilegios en langgenius/dify versión 0.9.1. Esta vulnerabilidad permite a un usuario normal modificar las instrucciones de Orchestrate para un chatbot creado por un usuario administrador. El problema surge porque la aplicación no aplica correctamente los controles de acceso en el endpoint /console/api/apps/{chatbot-id}/model-config, lo que permite que usuarios no autorizados alteren la configuración del chatbot.
CPE cpe:2.3:a:langgenius:dify:0.9.1:*:*:*:*:node.js:*:*
First Time Langgenius dify
Langgenius

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-14 17:25


NVD link : CVE-2024-11821

Mitre link : CVE-2024-11821

CVE.ORG link : CVE-2024-11821


JSON object : View

Products Affected

langgenius

  • dify
CWE
CWE-250

Execution with Unnecessary Privileges