CVE-2026-6617Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/api_tools_manage_service.py of the component ApiToolManageService. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-20: 2Technical Details · 2026-04-20: 104-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-6617 A vulnerability was detected in langgenius dify up to 0.6.9. This vulnerability affects the function get_api_tool_provider_remote_schema of the file api/services/tools/… https://www.cve.org/CVERecord?id=CVE-2026-6617

    Post summary

    The note announces the detection of CVE‑2026‑6617 in langgenius dify up to 0.6.9, identifying the affected function, but provides no further exploitation details or remediation information.

    0000089
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6617 Server-Side Request Forgery in Langgenius Dify Up To 0.6.9 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6617

    Post summary

    A newly disclosed SSRF vulnerability (CVE‑2026‑6617) affecting Langgenius Dify versions up to 0.6.9, with additional details linked to a vulnerability database page.

    0000041
    4.0K followersView on X

Explore more