CVE-2024-11821 Information
Mar 21, 2025
cve
Description
A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/chatbot-id/model-config allowing unauthorized users to alter chatbot configurations.
Reference
https://huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6
Share on: