Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-12775

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.2%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-12775
  • Langgenius » Dify » Version: 0.10.1
    cpe:2.3:a:langgenius:dify:0.10.1


Contact Us

Shodan ® - All rights reserved