CVE-2026-105762

CVE-2026-105762 published: Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. ...

View full NVD advisory → ← Back to CVE watch