Server-Side Request Forgery (SSRF) in Dify - #VU139841

 

Server-Side Request Forgery (SSRF) in Dify - #VU139841

Published: July 28, 2026


Vulnerability identifier: #VU139841
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LangGenius
Affected software:
Dify

Detailed vulnerability description

The vulnerability allows a remote attacker to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.

The vulnerability exists due to server-side request forgery in the /console/api/remote-files/upload endpoint when handling a user-supplied url parameter. A remote attacker can send a specially crafted request to make arbitrary HTTP requests to internal or external systems and disclose sensitive information.

Cloud metadata endpoints and otherwise inaccessible internal services may be reachable through the vulnerable server.


Remediation

Install security update from vendor's website.

Sources