Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langgenius
Langgenius dify |
|
| Vendors & Products |
Langgenius
Langgenius dify |
Mon, 05 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0. | |
| Title | Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T23:04:58.593Z
Reserved: 2026-10-05T19:11:07.948Z
Link: CVE-2026-105762
No data.
Status : Received
Published: 2026-10-06T00:16:33.090
Modified: 2026-10-06T00:16:33.090
Link: CVE-2026-105762
No data.
OpenCVE Enrichment
Updated: 2026-10-06T00:30:18Z
Weaknesses