{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-20T21:20:14.814","vulnerabilities":[{"cve":{"id":"CVE-2025-0184","sourceIdentifier":"security@huntr.dev","published":"2025-03-20T10:15:51.173","lastModified":"2025-07-15T15:41:34.817","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltype value is requested as a URL using the 'requests' module instead of the 'ssrf_proxy', leading to an SSRF vulnerability. This issue was fixed in version 0.11.0."},{"lang":"es","value":"Se identificó una vulnerabilidad de Server-Side Request Forgery (SSRF) en langgenius/dify versión 0.10.2. La vulnerabilidad se produce en la sección \"Crear conocimiento\" al subir archivos DOCX. Si existe una relación externa en el archivo DOCX, el valor reltype se solicita como URL mediante el módulo \"requests\" en lugar de \"ssrf_proxy\", lo que genera una vulnerabilidad SSRF. Este problema se solucionó en la versión 0.11.0."}],"metrics":{"cvssMetricV30":[{"source":"security@huntr.dev","type":"Secondary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security@huntr.dev","type":"Secondary","description":[{"lang":"en","value":"CWE-918"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*","versionEndExcluding":"0.11.0","matchCriteriaId":"BD57180F-1305-43F5-BD43-A397F3D3DE21"}]}]}],"references":[{"url":"https://github.com/langgenius/dify/commit/c135ec4b08d946a1a1d3a198a1d72c1ccf47250f","source":"security@huntr.dev","tags":["Patch"]},{"url":"https://huntr.com/bounties/a7eac4ae-5d5e-4ac1-894b-7a8cce5cba9b","source":"security@huntr.dev","tags":["Exploit","Third Party Advisory"]}]}}]}