CVE-2025-0185 - Dify Tools Vanna Module Pandas Query Injection Vulnerability
CVE-2025-0185 - Dify Tools Vanna Module Pandas Query Injection Vulnerability
CVE ID : CVE-2025-0185 Published : March 20, 2025, 10:15 a.m. | 2 days, 4 hours ago Description : A vulnerability in the Dify Tools’ Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function vn.get_training_plan_generic(df_information_schema)
, which does not properly sanitize
CVE ID : CVE-2025-0185
Published : March 20, 2025, 10:15 a.m. | 2 days, 4 hours ago
Description : A vulnerability in the Dify Tools’ Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more…