Dify’s real problem is not one bad endpoint. It is a broken trust boundary in a multi-tenant AI platform, where user-supplied IDs and forwarded internal requests can make another customer’s chats, uploaded files, and trace data look local. Three flaws are fixed in 1.14.2, but one disclosed CVE remains open, so patching does not fully close the leak.
Zafran’s DifyTap set covers four vulnerabilities in Dify. Two were unauthenticated, three had cross-tenant impact, and the affected paths include chat content, file preview, and internal plugin API calls; one issue also affects PDFium via CVE-2024-5846. The practical risk is that tenant data can cross into places scanners and basic patch checks may not prove clean, especially in deployments with shared AI chat, file, or trace features.