PT-2026-33730 · Langgenius · Dify

Eric-G

·

Published

2026-04-20

·

Updated

2026-04-20

·

CVE-2026-6617

CVSS v3.1

6.3

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get api tool provider remote schema of the file api/services/tools/api tools manage service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-6617

Affected Products

Dify