Impact
Langgenius Dify version 1.14.2 contains a flaw in the jinja2.Template function within the Jinja2 Handler that fails to properly neutralize special elements used in template rendering. This weakness can be exploited remotely to inject template code, potentially allowing an attacker to execute arbitrary code or manipulate the application logic. The issue is associated with CWE‑1336 (Code Injection) and CWE‑791 (Uncontrolled Refraction) and has a CVSS score of 5.3, indicating a moderate severity but with a clear path to compromise the affected host.
Affected Systems
The vulnerability affects the Langgenius Dify product, specifically all releases up to and including 1.14.2. No other vendors or versions are listed in the available data.
Risk and Exploitability
The exploit is publicly available and the vendor has not responded to disclosure, suggesting the flaw may already be in the wild. With a CVSS score of 5.3 and no EPSS data, the likelihood of a targeted attack is uncertain but the vulnerability is exploitable via any exposed API that processes user-supplied template content. The vulnerability is not listed in the CISA KEV catalog, yet its remote nature and available exploitation code increase the practical risk for running systems.
OpenCVE Enrichment