Summary
CVE-2026-105762 is an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Dify, the open-source LLM application development platform by LangGenius. The flaw resides in the /console/api/remote-files/upload endpoint, which fetches attacker-supplied URLs on the server’s behalf without any authentication or destination validation. The issue carries a CVSS v3.1 base score of 8.3 (High) and affects all Dify deployments running a version prior to 1.13.0.
Technical details
- Root cause: The remote file upload handler (
api/controllers/web/remote_files.py) accepts a user-controlledurlparameter and issues an outbound HTTP request to it without validating or restricting the destination (no allowlist/denylist for internal or reserved IP ranges). - Trigger conditions: An attacker sends an unauthenticated HTTP POST request to
/console/api/remote-files/uploadwith aurlfield pointing at an internal, loopback, or cloud metadata address. - Attack vector: Network-based (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N). The vulnerability has a scope change (S:C), meaning the impact can extend beyond the vulnerable component itself.
- Impact: The server can be coerced into making requests to internal-only services, cloud instance metadata endpoints (e.g., AWS/GCP metadata services), or other network-restricted resources, potentially disclosing sensitive internal data, credentials, or facilitating further lateral movement/reconnaissance within the hosting environment.
Affected software
- Dify (langgenius/dify) — all versions prior to 1.13.0
Severity
- CVSS v3.1 Base Score: 8.3 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Mitigation and recommended actions
- Immediate: Upgrade Dify to version 1.13.0 or later, which fixes the issue (addressed via PR #32236 / commit
2f87ecc0ce1d05ab3ef9537f29b84a5fa5823017). - If immediate patching is not possible:
- Restrict or disable public access to the
/console/api/remote-files/uploadendpoint at the network/reverse-proxy layer until patched. - Deploy egress filtering/firewall rules on the Dify host to block outbound requests to loopback, link-local, and private IP ranges (including
169.254.169.254cloud metadata addresses and RFC1918 ranges). - Disable or restrict access to cloud instance metadata services (e.g., require IMDSv2 on AWS) to reduce the blast radius of SSRF-based credential theft.
- Monitor outbound request logs from the Dify server for anomalous destinations.
- Restrict or disable public access to the

