Monitoring has detected that the server-side request forgery (SSRF) vulnerability exists in our unit's site: https://dify.xxxxx/console/api/remote-files/upload #22086

Closed
opened 2026-02-21 20:15:42 -05:00 by yindo · 1 comment
Owner

Originally created by @enniszhou on GitHub (Feb 5, 2026).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.11.1

Cloud or Self Hosted

Self Hosted (Docker)

Steps to reproduce

Monitoring has detected that the server-side request forgery (SSRF) vulnerability exists in our unit's site: https://dify.xxxxx/console/api/remote-files/upload. Attackers can use this vulnerability to conduct internal network probing and obtain server information. Not only can they steal data from your unit, but it can also be exploited to launch malicious attacks outward, threatening the cybersecurity of the public internet.

How should I modify it?

✔️ Expected Behavior

How should I modify it?

Actual Behavior

No response

Originally created by @enniszhou on GitHub (Feb 5, 2026). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.11.1 ### Cloud or Self Hosted Self Hosted (Docker) ### Steps to reproduce Monitoring has detected that the server-side request forgery (SSRF) vulnerability exists in our unit's site: https://dify.xxxxx/console/api/remote-files/upload. Attackers can use this vulnerability to conduct internal network probing and obtain server information. Not only can they steal data from your unit, but it can also be exploited to launch malicious attacks outward, threatening the cybersecurity of the public internet. How should I modify it? ### ✔️ Expected Behavior How should I modify it? ### ❌ Actual Behavior _No response_
yindo closed this issue 2026-02-21 20:15:42 -05:00
Author
Owner

@crazywoola commented on GitHub (Feb 5, 2026):

https://github.com/langgenius/dify/issues/31972#issuecomment-3851102807

@crazywoola commented on GitHub (Feb 5, 2026): https://github.com/langgenius/dify/issues/31972#issuecomment-3851102807
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#22086