CVE-2025-56520: SSRF
Published Sep 30, 2025
·Updated
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remotefiles.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.
Affected Software
2 affected components
Dify dify
Dify dify=1.6.0
Event History
Sep 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56520?
CVE-2025-56520 has been classified with a high severity due to its potential for exploiting server-side request forgery.
2
How do I fix CVE-2025-56520?
To fix CVE-2025-56520, ensure you upgrade to the latest version of Dify where the SSRF vulnerability is patched.
3
What impact does CVE-2025-56520 have on my system?
CVE-2025-56520 can allow attackers to interact with internal resources, making sensitive data accessible.
4
Which versions of Dify are affected by CVE-2025-56520?
CVE-2025-56520 affects Dify version 1.6.0 specifically.
5
Is CVE-2025-56520 related to any other vulnerabilities?
CVE-2025-56520 is a distinct vulnerability from CVE-2025-29720, focusing on a different server-side request forgery issue.