CVE-2026-105762: Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remotefiles.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Difyto a version that resolves this vulnerability.Fixed in 1.13.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Any remote attacker who can reach the affected Dify endpoint can exploit it. No authentication, prior privileges, or user interaction are required.
Which deployments are affected?
Dify versions prior to 1.13.0 are affected if the /console/api/remote-files/upload endpoint is reachable by an attacker. The issue is fixed in version 1.13.0.
What can an attacker do through this vulnerability?
An attacker can cause the Dify server to make requests to attacker-chosen URLs, including internal services or cloud metadata endpoints. This may expose sensitive data and allow the server to be used as a network pivot.