Dify v1.6.0 contains a server side request forgery caused by improper validation in controllers.console.remote_files.RemoteFileUploadApi, letting attackers make arbitrary requests from the server, exploit requires network access.
id: CVE-2025-56520
info:
name: Dify v1.6.0 - Server-Side Request Forgery
author: 0x_Akoko
sev
...