CVE-2026-41948
CVSS 9.4 CRITICAL: dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate… EPSS 7% (94th percentile).
Vulnerabilities · 83 days ago
Dify’s real problem is not one bad endpoint. It is a broken trust boundary in a multi-tenant AI platform, where user-supplied IDs and forwarded internal requests can make another customer’s chats, uploaded files, and trace data look local. Three flaws are fixed in 1.14.2, but one disclosed CVE remains open, so patching does not fully close the leak.
Zafran’s DifyTap set covers four vulnerabilities in Dify. Two were unauthenticated, three had cross-tenant impact, and the affected paths include chat content, file preview, and internal plugin API calls; one issue also affects PDFium via CVE-2024-5846. The practical risk is that tenant data can cross into places scanners and basic patch checks may not prove clean, especially in deployments with shared AI chat, file, or trace features.
CVSS 9.4 CRITICAL: dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate… EPSS 7% (94th percentile).
CVSS 9.1 CRITICAL: dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to… EPSS 6% (93rd percentile), up from 0.5%.
CVSS 5.9 MEDIUM: dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows… EPSS 0.4% (35th percentile).
CVSS 6.5 MEDIUM: dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the… EPSS 0.3% (27th percentile).
3 sources covering this story
Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Attackers could abuse Dify's multi-tenant cloud service to read private chats, preview other tenants' documents, and reach internal APIs.
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Four DifyTap flaws could expose private AI chats and files across Dify tenants; three are fixed in version 1.14.2.
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access sensitive data.
Part of the PlainSec briefing for 2026-06-24