Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

langgenius — Vulnerabilities & Security Advisories 38

Browse all 38 CVE security advisories affecting langgenius. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Langgenius operates as an open-source, self-hosted large language model application development platform, enabling organizations to build and deploy custom AI interfaces. With thirty-two recorded Common Vulnerabilities and Exposures, the software has historically exhibited significant security flaws, primarily involving remote code execution, cross-site scripting, and broken access control mechanisms. These vulnerabilities often stem from improper input validation and insufficient authentication checks within the application’s API layers. Notably, several incidents have highlighted critical privilege escalation risks, allowing unauthorized users to gain administrative access or execute arbitrary commands on the host system. The platform’s architecture, which relies heavily on external dependencies and complex integrations, has contributed to its attack surface. While designed for enterprise flexibility, these recurring security issues underscore the necessity for rigorous patch management and strict configuration controls to mitigate potential exploitation by malicious actors seeking to compromise underlying infrastructure.

Found 14 results / 38 Clear Filters
Top products by langgenius: dify langgenius/dify
CVE ID Title CVSS Severity Published
CVE-2025-11750 User Enumeration via Distinct Error Messages in langgenius/dify-web — langgenius/dify CWE-544 8.2AI High AI 2025-10-22
CVE-2025-3467 XSS Vulnerability in langgenius/dify — langgenius/dify CWE-79 6.1AI Medium AI 2025-07-07
CVE-2025-3466 Unsanitized Input in langgenius/dify — langgenius/dify CWE-1100 9.8AI Critical AI 2025-07-07
CVE-2025-0184 Server-Side Request Forgery (SSRF) in langgenius/dify — langgenius/dify CWE-918 9.1 - 2025-03-20
CVE-2024-11850 Stored XSS in langgenius/dify — langgenius/dify CWE-79 5.4 - 2025-03-20
CVE-2024-12776 Authentication Bypass in langgenius/dify — langgenius/dify CWE-305 9.8 - 2025-03-20
CVE-2024-10252 Code Injection in langgenius/dify — langgenius/dify CWE-94 9.8 - 2025-03-20
CVE-2024-12039 Improper Restriction of Excessive Authentication Attempts in langgenius/dify — langgenius/dify CWE-307 9.8 - 2025-03-20
CVE-2024-12775 SSRF in langgenius/dify — langgenius/dify CWE-918 9.1 - 2025-03-20
CVE-2024-11822 Server-Side Request Forgery (SSRF) in langgenius/dify — langgenius/dify CWE-918 7.5 - 2025-03-20
CVE-2025-0185 Pandas Query Injection in langgenius/dify — langgenius/dify CWE-94 9.8 - 2025-03-20
CVE-2024-11824 Stored XSS in langgenius/dify — langgenius/dify CWE-79 5.4 - 2025-03-20
CVE-2024-11821 Privilege Escalation in langgenius/dify — langgenius/dify CWE-250 5.7 - 2025-03-20
CVE-2025-1796 Admin account takeover through weak Pseudo-Random number generator used in generating password reset codes in langgenius/dify — langgenius/dify CWE-338 8.8 - 2025-03-20

This page lists every published CVE security advisory associated with langgenius. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.