CVE-2026-105762

CVE & Vulnerabilities · October 8, 2026

CVE & Vulnerabilities·nvd.nist.gov

CVE-2026-105762 affects Dify, an open-source platform for building LLM applications: versions before 1.13.0 exposed a file-upload endpoint that fetched any attacker-supplied URL without requiring authentication. That let a remote attacker force the server to reach internal services or cloud metadata APIs, potentially leaking secrets or turning the server into a pivot point for further attacks. The project patched the flaw in version 1.13.0, so upgrading closes the hole.

// source: nvd.nist.gov ↗

← Back to Blog