Dify < 1.13.0 - Unauthenticated SSRF via Remote File Upload
Detected Dify prior to 1.13.0 is vulnerable to unauthenticated Server-Side Request Forgery via the /console/api/remote-files/upload endpoint. The endpoint accepted a user-controlled URL parameter and issued HTTP requests from the server without authentication or SSRF protections such as private IP blocking.