A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to inject malicious HTML into the log via prompts. When an admin views the log containing the malicious HTML, the attacker could steal the admin's credentials or sensitive information. This issue is fixed in version 0.12.1.
Metrics
Affected Vendors & Products
References
History
Mon, 14 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langgenius
Langgenius dify |
|
CPEs | cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Langgenius
Langgenius dify |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like <input> and <form> are not disallowed, allowing an attacker to inject malicious HTML into the log via prompts. When an admin views the log containing the malicious HTML, the attacker could steal the admin's credentials or sensitive information. This issue is fixed in version 0.12.1. | |
Title | Stored XSS in langgenius/dify | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:09:08.878Z
Updated: 2025-03-20T18:57:34.961Z
Reserved: 2024-11-26T17:53:12.411Z
Link: CVE-2024-11824

Updated: 2025-03-20T17:51:39.394Z

Status : Analyzed
Published: 2025-03-20T10:15:25.790
Modified: 2025-07-14T17:42:04.233
Link: CVE-2024-11824

No data.