{"id":"CVE-2024-12775","summary":"SSRF in langgenius/dify","details":"langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.","modified":"2026-08-12T03:51:28.301891708Z","published":"2025-03-20T10:09:23.407Z","database_specific":{"cna_assigner":"@huntr_ai","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12775.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/e90e929a-9bc9-46ad-a5e5-1f6f124d0f12"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12775.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12775"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/langgenius/dify","events":[{"introduced":"400392230b47fff5d011b55afd8b0f8b8083ade0"},{"last_affected":"400392230b47fff5d011b55afd8b0f8b8083ade0"}],"database_specific":{"extracted_events":[{"introduced":"0.10.1"},{"last_affected":"0.10.1"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:langgenius:dify:0.10.1:*:*:*:*:node.js:*:*"}}],"versions":["0.10.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-12775.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}