CVE-2024-12775
CVSS 3.0 Score 6.5 of 10 (medium)
Details
Published Mar 20, 2025
CWE ID 918
Summary
CVE-2024-12775 is a Server-Side Request Forgery (SSRF) vulnerability affecting version 0.10.1 of langgenius/dify's Create Custom Tool option via the REST API. The issue lies in the test functionality, where attackers can manipulate the `url` in the `servers` dictionary within OpenAI's schema to direct arbitrary requests to unauthorized web resources on the victim server. This can potentially lead to unauthorized access and misuse of the victim's credentials.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Dify