Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langgenius
Langgenius dify |
|
| Vendors & Products |
Langgenius
Langgenius dify |
Mon, 05 Oct 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0. | |
| Title | Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T23:04:58.593Z
Reserved: 2026-10-05T19:11:07.948Z
Link: CVE-2026-105762
No data.
Status : Received
Published: 2026-10-06T00:16:33.090
Modified: 2026-10-06T00:16:33.090
Link: CVE-2026-105762
No data.
OpenCVE Enrichment
Updated: 2026-10-06T00:30:18Z