Remote File Upload Vulnerability in Dify Open-Source LLM Development Platform
CVE-2026-105762

8.3HIGH

Key Information:

Vendor

Langgenius

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105762?

Dify, an open-source platform for LLM app development, has a vulnerability in its /console/api/remote-files/upload endpoint prior to version 1.13.0. This flaw allows unauthenticated remote attackers to upload files from malicious URLs, leading to potential exposure of sensitive data and allowing attackers to access internal services or cloud metadata endpoints. The vulnerability has been addressed in version 1.13.0, which reinforces the need for users to update promptly to prevent exploitation.

Affected Version(s)

dify < 1.13.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.