References https://nvd.nist.gov/vuln/detail/CVE-2025-11750 https://access.redhat.com/security/cve/cve-2025-11750 https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-11750.yaml https://cve.imfht.com/detail/CVE-2025-11750?lang=en https://www.kodemsecurity.com/cve-database/cve-2025-11750 https://huntr.com/repos/langgenius/dify https://www.thehackerwire.com/vulnerability/CVE-2025-11750/ https://github.com/langgenius/dify/security/advisories/GHSA-9qpf-wcv3-w3qx https://huntr.com/bounties/e7359f9f-c004-4304-9de9-753622d370a1 https://cve.imfht.com/detail/CVE-2025-11750 https://www.ddpoc.com/DVB-2026-10746.html
Related VulnerabilitiesPoCdify-ssrf-remote-upload: Dify < 1.13.0 - Unauthenticated SSRF via Remote File UploadPoCCVE-2026-28288: Dify User Enumeration via Observable Response DiscrepancyDify /console/api/remote-files/ 服务器端请求伪造漏洞(CVE-2025-56520)PoCCVE-2025-56520: Dify v1.6.0 - Server-Side Request ForgeryPoCCVE-2025-63387: Dify v1.9.1 - Broken Access ControlDify存在远程命令执行漏洞Dify /console/api/remote-files/upload 服务器端请求伪造漏洞western-digital-mycloud-multi-uploadify-file-upload: Western Digital MyCloud Multi Uploadify File UploadPoCweaver-lazyuploadify-file-upload: OA E-Office LazyUploadify - Arbitrary File UploadPoCweaver-uploadify-file-upload: OA E-Office Uploadify - Arbitrary File UploadPoCCVE-2025-11750: Dify - User Enumeration via "Account not found" MessageDify存在SSRF漏洞(CVE-2025-29720)