Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the sear…
高危 CVSS 8.8
摘要
Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判 · 自动通道
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- https://github.com/langgenius/dify/commit/d9884efaeea8322706e24c560d2c17e5bf3fab5f Patch
- https://github.com/langgenius/dify/issues/38281 Issue Tracking
- https://github.com/langgenius/dify/pull/38295 Issue Tracking
- https://github.com/langgenius/dify/releases/tag/1.16.0-rc1 Release Notes
- https://www.vulncheck.com/advisories/dify-rc1-sql-injection-via-myscale-vector-store-search-by-full-text Third Party Advisory
时间线
- nvd_ingest NVD