Sploitus

CVE-2024-12775

No indexed exploits for CVE-2024-12775 yet

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.

Affected products
Openai, Langgenius/Dify
Langgenius Dify
= 0.10.1
Fix
Available
CVSS 3.0
6.5 MEDIUM
EPSS
0.6% (48th percentile)
Weakness
CWE-918
NVD status
Analyzed
Published
2025-03-20
CVE-2024-12775 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-12775 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-12775 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.