[PR #31678] fix: SSRF in WordExtractor URL download (credit to @EaEa0001 ) #33351

Closed
opened 2026-02-21 20:53:07 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/31678

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

Route WordExtractor remote .docx downloads through core.helper.ssrf_proxy instead of direct httpx.get, and add a unit test to cover it. Also tightens ssrf_proxy request typing/validation and adds explicit remote_url guards for strict type checking.

Credit: tim.zheng (GitHub: @EaEa0001) for reporting this issue.

Screenshots

Before After
N/A N/A

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend). (No frontend changes.)
**Original Pull Request:** https://github.com/langgenius/dify/pull/31678 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary Route WordExtractor remote `.docx` downloads through `core.helper.ssrf_proxy` instead of direct `httpx.get`, and add a unit test to cover it. Also tightens `ssrf_proxy` request typing/validation and adds explicit `remote_url` guards for strict type checking. Credit: tim.zheng (GitHub: @EaEa0001) for reporting this issue. ## Screenshots | Before | After | |--------|-------| | N/A | N/A | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `make lint` and `make type-check` (backend). (No frontend changes.)
yindo added the pull-request label 2026-02-21 20:53:07 -05:00
yindo closed this issue 2026-02-21 20:53:07 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33351