CVE-2026-105762 - Dify: Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint
CVE ID :CVE-2026-105762 Published : Oct. 6, 2026, 12:16 a.m. | 1 hour, 11 minutes ago Description :Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL...