/Vulnerability Library

Dify v1.6.0 - Server-Side Request Forgery

CVE-2025-56520
Verified

Description

Dify v1.6.0 contains a server side request forgery caused by improper validation in controllers.console.remote_files.RemoteFileUploadApi, letting attackers make arbitrary requests from the server, exploit requires network access.

Severity

High

CVSS Score

9.3

Exploit Probability

1%

Published Date

January 20, 2026

Template Author

0x_akoko

CVE-2025-56520.yaml
9.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CVE ID:
cve-2025-56520
CWE ID:
cwe-918

References

https://github.com/langgenius/difyhttps://dify.ai/

Remediation Steps

Update to the latest version.