Vulnerability
Published 2026-10-05
Verified 2026-10-06

Dify CVE-2026-105762 (CVSS 8.3): unauthenticated SSRF in the remote-files upload endpoint can reach internal services and cloud metadata (fixed 1.13.0); CVE-2026-105761 MCP server IDOR across apps (fixed 1.16.0)

Two CVE records for Dify, the open-source LLM app development platform from LangGenius, were published on 5 October 2026 from its GitHub advisories. GHSA-8235-vv5j-mmvg (CVE-2026-105762, CVSS 3.1 8.3): before 1.13.0, the /console/api/remote-files/upload endpoint took an attacker-supplied URL without authentication and made the Dify server fetch it, so a remote attacker could use the server to send requests to internal services or cloud metadata endpoints and as a network pivot. GHSA-ccrj-frp2-c945 (CVE-2026-105761, 7.1): before 1.16.0, the PUT endpoint for an app's MCP server looked up the server by a client-supplied ID without checking that it belonged to that app and tenant, so an authenticated workspace member could change another app's MCP server status and settings, potentially redirecting data or disabling the service. The advisories do not report exploitation. Primary: Dify GitHub security advisories; CVE records 5 Oct.

Product
Dify (LangGenius) self-hosted LLM app platform — API service
Versions
CVE-2026-105762: before 1.13.0. CVE-2026-105761: before 1.16.0. Fixed: 1.16.0 or later covers both.
CVSS
(CVSS 3.1, CVE-2026-105762); 7.1 (CVE-2026-105761)
Exploited in Australia?
unknown
Patch to
Upgrade self-hosted Dify to 1.16.0 or later. On cloud hosts, require IMDSv2 or the provider's equivalent and block the API container from reaching metadata and internal admin ranges with egress rules, so any remaining SSRF has nowhere useful to go.

Primary: Dify GHSA-8235-vv5j-mmvg — Unauthenticated SSRF in /console/api/remote-files/upload (CVE-2026-105762) · Vendor: Dify GHSA-ccrj-frp2-c945 — IDOR in AppMCPServer PUT endpoint (CVE-2026-105761) · CVE: CVE-2026-105762, CVE-2026-105761 · Dify — GitHub security advisories index

tech ai cloud