A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG content, which can execute arbitrary JavaScript code when viewed by an admin, potentially leading to credential theft.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Langgenius
Langgenius dify |
|
CPEs | cpe:2.3:a:langgenius:dify:0.9.2:*:*:*:*:node.js:*:* | |
Vendors & Products |
Langgenius
Langgenius dify |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG content, which can execute arbitrary JavaScript code when viewed by an admin, potentially leading to credential theft. | |
Title | Stored XSS in langgenius/dify | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:55.421Z
Updated: 2025-03-20T18:14:58.033Z
Reserved: 2024-11-26T21:17:14.506Z
Link: CVE-2024-11850

Updated: 2025-03-20T17:47:48.195Z

Status : Analyzed
Published: 2025-03-20T10:15:25.913
Modified: 2025-07-15T16:00:30.000
Link: CVE-2024-11850

No data.