CVE-2026-105762
Received Received - Intake

Remote File Upload Vulnerability in Dify

Vulnerability report for CVE-2026-105762, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: GitHub, Inc.

Description

Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
langgenius dify < 1.13.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Dify affecting versions prior to 1.13.0. The flaw exists in the /console/api/remote-files/upload endpoint where attackers can send arbitrary HTTP requests from the Dify server to internal or external systems by providing a URL parameter without authentication.

Detection Guidance

Check if your Dify instance is running a version prior to 1.13.0 by running: curl -s http://<dify-server>/api/version | grep version. If the version is below 1.13.0, the system is vulnerable. Inspect network logs for outbound requests from the Dify server to internal or external systems, particularly to private/reserved IP ranges or cloud metadata endpoints. Use tools like tcpdump or Wireshark to monitor traffic originating from the Dify server.

Impact Analysis

An attacker could use this vulnerability to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data. They could also use the Dify server as a network pivot to move laterally within networks or perform denial-of-service attacks.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Exposure of internal services or metadata could result in regulatory penalties.

Mitigation Strategies

Upgrade Dify to version 1.13.0 or later immediately. If upgrading is not possible, restrict outbound requests from the Dify server by implementing strict allow-lists or deny-lists for URLs. Block private/reserved IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.0/8) and enforce DNS rebinding protections. Ensure all API endpoints require authentication by verifying the presence of @login_required decorators in the remote_files.py controller.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105762. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart