CVE-2025-29720
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_fi
Dify v1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi.
MEDIUM · CVSS 4.8
EPSS 0.00068
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0