← Back to CVE List

CVE-2025-0185

Published: 2025-03-20T10:15Z
Last Modified: 2025-03-27T19:18Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt