CVE-2026-105762 | LangGenius Dify up to 1.12.x Remote File Upload remote_files.py server-side request forgery

SecurityVulns

A vulnerability marked as critical has been reported in LangGenius Dify up to 1.12.x. Affected by this issue is some unknown functionality of the file api/controllers/web/remote_files.py of the component Remote File Upload. Performing a manipulation results in server-side request forgery.

This vulnerability is known as CVE-2026-105762. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More