CVE-2025-29720: SSRF
Published Apr 14, 2025
·Updated
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remotefiles.RemoteFileUploadApi.
Affected Software
2 affected components
Dify dify
LangGenius Dify Node.js=1.0.0
Event History
Apr 14, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-29720?
CVE-2025-29720 has a high severity due to its potential for Server-Side Request Forgery, leading to unauthorized access to internal services.
2
How do I fix CVE-2025-29720?
To fix CVE-2025-29720, ensure that proper input validation and access control are implemented in the affected component, preventing malicious requests.
3
What software is affected by CVE-2025-29720?
CVE-2025-29720 affects Dify version 1.0, which has been identified as vulnerable to SSRF attacks.
4
What type of vulnerability is CVE-2025-29720?
CVE-2025-29720 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
Can CVE-2025-29720 be exploited remotely?
Yes, CVE-2025-29720 can be exploited remotely, allowing attackers to send unauthorized requests through the server.