Record summary

CVE-2026-6617 has a selected CVSS score of 5.3 (medium).

Description

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 20, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List0.6.0affected
0.6.1affected
0.6.2affected
0.6.3affected
0.6.4affected
0.6.5affected
0.6.6affected
0.6.7affected
0.6.8affected
0.6.9affected

References

5
VDB-358252 | langgenius dify ApiToolManageService api_tools_manage_service.py get_api_tool_provider_remote_schema server-side request forgeryvdb entryTechnical description
https://vuldb.com/vuln/358252