PT-2025-40009 · Dify · Dify

Ki9Mu

·

Published

2025-09-30

·

Updated

2026-01-20

·

CVE-2025-56520

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dify version 1.6.0
Description The software contains a Server-Side Request Forgery (SSRF) issue. This occurs due to improper validation within the controllers.console.remote files.RemoteFileUploadApi component. An attacker could potentially leverage this to make requests on behalf of the server, potentially accessing internal resources or performing unauthorized actions.
Recommendations Update to a newer version that contains a fix for this vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-56520

Affected Products

Dify