Vulnerability  ·  2026-10-07

Dify unauthenticated SSRF in remote-files upload — reaches internal services and cloud metadata

VulnerabilityHigh impactGlobalCVE-2026-105762
The unauthenticated /console/api/remote-files/upload endpoint accepted an attacker-controlled URL and caused the Dify server to fetch it (CWE-918 SSRF). A remote attacker can direct the LLM-platform server against internal services or cloud metadata endpoints (169.254.169.254), exposing sensitive data and allowing the server to be used as a network pivot. Fixed in Dify 1.13.0; CISA SSVC marks it exploitation=poc and automatable=yes.
Dify is a widely deployed open-source LLM app-development platform. An unauthenticated, automatable SSRF in the console remote-file handler gives attackers direct read access to cloud IAM/instance metadata and internal APIs from inside a tenant that often holds model API keys and RAG document stores — no account needed.
POST a URL pointing at 169.254.169.254/latest/meta-data or an internal service to /console/api/remote-files/upload; Dify server fetches it and reflects/stores the response.
Dify (langgenius/dify) < 1.13.0
Upgrade to Dify 1.13.0; block egress to link-local/internal ranges at the network layer if upgrade is delayed.
NVD CVE-2026-105762GitHub advisory GHSA-8235-vv5j-mmvgThreatFrontier Dify SSRF analysis
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →