Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Ki9Mu

#47557of 53,624
5.3Total CVSS
Vulnerabilities · 1
PT-2025-40009
5.3
2025-09-30
Dify · Dify · CVE-2025-56520
**Name of the Vulnerable Software and Affected Versions** Dify version 1.6.0 **Description** The software contains a Server-Side Request Forgery (SSRF) issue. This occurs due to improper validation within the `controllers.console.remote files.RemoteFileUploadApi` component. An attacker could potentially leverage this to make requests on behalf of the server, potentially accessing internal resources or performing unauthorized actions. **Recommendations** Update to a newer version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.