CVE-2026-41948
CVSS 9.4 CRITICAL: dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate… EPSS 2% (79º percentile).
Vulnerabilità · 98 giorni fa
Il problema non è un singolo bug applicativo: è il confine tra tenant a cedere in una piattaforma AI che conserva chat, file e trace per più clienti. In Dify, un utente autenticato può farsi restituire dati di un altro tenant o colpire un endpoint interno come se fosse legittimo, perché gli ID e le richieste inoltrate vengono fidati troppo.
Zafran ha descritto quattro flaw DifyTap: tre sono corrette in Dify 1.14.2 e una resta aperta, con impatto su chat, file e chiamate al Plugin Daemon. Le issue includono bypass di autorizzazione su trace e file preview, traversal verso endpoint privati interni e il riuso di un file UUID per leggere documenti altrui; la stessa pipeline di parsing dei file espone anche CVE-2024-5846 in PDFium.
Qui la correzione del vendor non chiude tutto. Le differenze tra immagini container possono lasciare la vulnerabilità nascosta agli scanner, e chi gestisce installazioni multi-tenant deve trattare chat, file caricati e dati di trace come esposti oltre il perimetro del tenant fino a verifica esplicita della presenza di CVE-2026-41950.
CVSS 9.4 CRITICAL: dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate… EPSS 2% (79º percentile).
CVSS 9.1 CRITICAL: dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to… EPSS 0.6% (47º percentile).
CVSS 5.9 MEDIUM: dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows… EPSS 0.6% (45º percentile).
CVSS 6.5 MEDIUM: dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the… EPSS 0.5% (38º percentile).
3 fonti che coprono questa storia
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Four DifyTap flaws could expose private AI chats and files across Dify tenants; three are fixed in version 1.14.2.
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access sensitive data.
Part of the PlainSec briefing for 2026-06-24