References https://www.cnblogs.com/zhengna/p/19325696 https://cloud.tencent.com/developer/article/2607793 https://avd.aliyun.com/detail?id=AVD-2024-12776 https://zhuanlan.zhihu.com/p/1986735185866298423 https://github.com/YFGaia/dify-plus/wiki/20251205-%E5%A6%82%E4%BD%95%E8%87%AA%E6%B5%8B%E7%89%88%E6%9C%AC%E5%92%8C%E7%9A%84react%E6%BC%8F%E6%B4%9E https://view.inews.qq.com/a/20251213A049WL00 https://www.cnblogs.com/chenlifan/p/19332757 https://avd.aliyun.com/detail?id=AVD-2025-29720 https://www.varmor.org/zh-cn/blog/harden-the-AI-application-development-platform https://app.opencve.io/cve/?vendor=dify https://nvd.nist.gov/vuln/detail/CVE-2025-58747 https://github.com/langgenius/dify/security/advisories https://forum.dify.ai/t/security-update/258 https://nvd.nist.gov/vuln/detail/CVE-2025-55182
Related VulnerabilitiesPoCdify-ssrf-remote-upload: Dify < 1.13.0 - Unauthenticated SSRF via Remote File UploadPoCCVE-2026-28288: Dify User Enumeration via Observable Response DiscrepancyDify /console/api/remote-files/ 服务器端请求伪造漏洞(CVE-2025-56520)Dify存在用户名枚举漏洞(CVE-2025-11750)PoCCVE-2025-56520: Dify v1.6.0 - Server-Side Request ForgeryPoCCVE-2025-63387: Dify v1.9.1 - Broken Access ControlDify存在远程命令执行漏洞Dify /console/api/remote-files/upload 服务器端请求伪造漏洞western-digital-mycloud-multi-uploadify-file-upload: Western Digital MyCloud Multi Uploadify File UploadPoCweaver-lazyuploadify-file-upload: OA E-Office LazyUploadify - Arbitrary File UploadPoCweaver-uploadify-file-upload: OA E-Office Uploadify - Arbitrary File UploadPoCCVE-2025-11750: Dify - User Enumeration via "Account not found" Message