← Vulnerability feed

Vulnerability record · CVE-2025-0185 · published 20 March 2025

CVE-2025-0185: Dify code injection vulnerability

Dify · Dify

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited.

8.8 CVSS 3.1 High EPSS 1.1% · top 35.7% CWE-94 · Code injection
8.8CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://huntr.com/bounties/7d9eb9b2-7b86-45ed-89bd-276c1350db7e ExploitIssue TrackingThird Party Advisory
https://huntr.com/bounties/7d9eb9b2-7b86-45ed-89bd-276c1350db7e ExploitIssue TrackingThird Party Advisory

Track CVE-2025-0185 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2026-41947Dify insecure direct object reference vulnerabilityDify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio…EPSS 0.61%9.3CVE-2026-41948Dify relative path traversal vulnerabilityDify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D…EPSS 1.9%8.7CVE-2026-61461Dify sql injection vulnerabilityDify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s…EPSS 0.50%8.4CVE-2025-67732Dify information exposure vulnerabilityDify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin…EPSS 0.35%8.2CVE-2026-41949Dify insecure direct object reference vulnerabilityDify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up …EPSS 0.57%7.5CVE-2024-11822Dify server-side request forgery (ssrf) vulnerabilitylanggenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a…EPSS 0.60%5.5CVE-2026-28288Dify vulnerabilityDify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowi…EPSS 0.71%5.3CVE-2026-34082Dify improper access control vulnerabilityDify is an open-source LLM app development platform. Prior to 1.13.1, the method `DELETE /console/api/installed-apps/<appId>/conversations/<conversat…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2025-0185), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.