---
id: CVE-2026-105762
title: Dify is an open-source LLM app development platform
summary: >-
  Dify is an open-source LLM app development platform. Prior to 1.13.0, the
  /console/api/remote-files/upload endpoint in
  api/controllers/web/remote_files.py accepted an attacker-controlled URL
  without authentication and caused the Dify ser…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L'
cwe:
  - CWE-918
vendor: langgenius
product: dify
affected:
  - dify < 1.13.0
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T00:16:33.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105762'
references:
  - url: >-
      https://github.com/langgenius/dify/commit/2f87ecc0ce1d05ab3ef9537f29b84a5fa5823017
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/pull/32236'
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/releases/tag/1.13.0'
    label: security-advisories@github.com
  - url: 'https://github.com/langgenius/dify/security/advisories/GHSA-8235-vv5j-mmvg'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T23:36:21.189Z'
---

## Overview

Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
