Dify CVE-2026-105762 (CVSS 8.3): unauthenticated SSRF in the remote-files upload endpoint can reach internal services and cloud metadata (fixed 1.13.0); CVE-2026-105761 MCP server IDOR across apps (fixed 1.16.0)
Two CVE records for Dify, the open-source LLM app development platform from LangGenius, were published on 5 October 2026 from its GitHub advisories. GHSA-8235-vv5j-mmvg (CVE-2026-105762, CVSS 3.1 8.3): before 1.13.0, the /console/api/remote-files/upload endpoint took an attacker-supplied URL without authentication and made the Dify server fetch it, so a remote attacker could use the server to send requests to internal services or cloud metadata endpoints and as a network pivot. GHSA-ccrj-frp2-c945 (CVE-2026-105761, 7.1): before 1.16.0, the PUT endpoint for an app's MCP server looked up the server by a client-supplied ID without checking that it belonged to that app and tenant, so an authenticated workspace member could change another app's MCP server status and settings, potentially redirecting data or disabling the service. The advisories do not report exploitation. Primary: Dify GitHub security advisories; CVE records 5 Oct.
- Product
- Dify (LangGenius) self-hosted LLM app platform — API service
- Versions
- CVE-2026-105762: before 1.13.0. CVE-2026-105761: before 1.16.0. Fixed: 1.16.0 or later covers both.
- CVSS
- (CVSS 3.1, CVE-2026-105762); 7.1 (CVE-2026-105761)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L - Exploited in Australia?
- unknown
- Patch to
- Upgrade self-hosted Dify to 1.16.0 or later. On cloud hosts, require IMDSv2 or the provider's equivalent and block the API container from reaching metadata and internal admin ranges with egress rules, so any remaining SSRF has nowhere useful to go.
Primary: Dify GHSA-8235-vv5j-mmvg — Unauthenticated SSRF in /console/api/remote-files/upload (CVE-2026-105762) · Vendor: Dify GHSA-ccrj-frp2-c945 — IDOR in AppMCPServer PUT endpoint (CVE-2026-105761) · CVE: CVE-2026-105762, CVE-2026-105761 · Dify — GitHub security advisories index
