CVE-2024-11850

Source
https://cve.org/CVERecord?id=CVE-2024-11850
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11850.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-11850
Published
2025-03-20T10:10:55.421Z
Modified
2026-08-12T03:51:35.571778242Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N CVSS Calculator
Summary
Stored XSS in langgenius/dify
Details

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG content, which can execute arbitrary JavaScript code when viewed by an admin, potentially leading to credential theft.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/11xxx/CVE-2024-11850.json",
    "cna_assigner": "@huntr_ai"
}
References

Affected packages

Git / github.com/langgenius/dify

Affected ranges

Type
GIT
Repo
https://github.com/langgenius/dify
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:langgenius:dify:0.9.2:*:*:*:*:node.js:*:*",
    "source": "CPE_STRING",
    "extracted_events": [
        {
            "introduced": "0.9.2"
        },
        {
            "last_affected": "0.9.2"
        }
    ]
}

Affected versions

0.*
0.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-11850.json"