CVE-2025-56520Active Exploitation(dify / dify)

LOWCVSS 5.3 · MEDIUM

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for dify dify systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different vulnerability than CVE-2025-29720.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dify

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
dify

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-16: 2Active Exploitation · 2026-02-16: 1Technical Details · 2026-02-16: 102-16
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 This week’s CrowdSec Threat Alert: CVE-2025-56520, an actively exploited SSRF vulnerability in Dify, is enabling reconnaissance and internal network probing across exposed AI platforms. Discover attack patterns, momentum trends, and mitigation steps in our latest article 👉 https://www.crowdsec.net/vulntracking-report/cve-2025-56520 #CVE #CVE202556520 #threatalert #Dify #cybersecurity

    Post summary

    CrowdSec reports that CVE-2025-56520, an SSRF flaw in Dify, is currently being exploited for reconnaissance and internal network probing on exposed AI platforms.

    00130451
    19.6K followersView on X
  • SAQER@saqer_one
    General

    CVE-2025-56520:加速する「理解」の欠如 教訓:AI管理への過信と盲点Difyの脆弱性が放置されたのは、管理ボット(AI)が報告を勝手に終了させたためです。「便利さ」に甘んじて人間が管理の細部から目を離すと、重大なリスクが埋没するという教訓です。 👇

    Post summary

    The passage warns about complacency with AI‑managed systems in the context of CVE‑2025‑56520, but offers no technical or exploit specifics.

    1001091
    12.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdifydify1.6.0--

Explore more