Security researchers have disclosed a set of four vulnerabilities in Dify, an open-source agentic workflow platform, that could allow attackers to covertly intercept and read artificial intelligence conversations from other customers’ applications without requiring any authentication. The flaws, collectively named DifyTap by Zafran Security, expose a critical weakness in the platform’s multi-tenant architecture, putting sensitive data from millions of users at risk.
Two of the vulnerabilities are classified as critical severity, two require no authentication to exploit, and three carry cross-tenant impact on Dify’s cloud service. This architecture allows one customer’s data to be exposed to another, creating a silent and persistent exfiltration channel for every message and model response flowing through the system, according to researchers Ido Shani and Gal Zaban.
The DifyTap Vulnerabilities: A Technical Breakdown
The set of four CVEs targets different aspects of Dify’s infrastructure, from authorization bypasses to path traversal. The most severe of these, CVE-2026-41947, carries a CVSS score of 9.1 and allows an authenticated editor user to set and enable trace configurations for any application, regardless of tenant ownership. This missing tenant ownership check can be weaponized to redirect all messages and responses from victim applications to an attacker-controlled LLM trace provider. Since anyone can freely register for a Dify account, the barrier to entry for this attack is minimal.
Critical Authorization and Path Traversal Flaws
CVE-2026-41948 (CVSS score: 9.4) is a path traversal vulnerability. It allows authenticated users to manipulate requests forwarded to Dify’s internal Plugin Daemon API by exploiting insufficient URL path sanitization. This enables access to internal, private endpoints from unauthenticated requests, effectively breaking the security perimeter of the platform.
CVE-2026-41949 (CVSS score: 7.5/5.9) is an authorization bypass vulnerability in the file preview endpoint, located at /console/api/files/{file_id}/previewcodecodecode. This flaw allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file’s UUID. This represents a direct breach of tenant isolation, as an attacker can preview sensitive documents uploaded by a completely different organization.
Cross-Tenant and Intra-Tenant Data Leakage
CVE-2026-41950 (CVSS score: 6.5) is an authorization bypass that allows authenticated users to read the full contents of files uploaded by other users within the same tenant. This is achieved by simply supplying an arbitrary file UUID in the files array of a chat-messages request. Combined, these flaws allow an attacker to create a persistent exfiltration channel, enabling them to silently wiretap all AI conversations and access sensitive documents.
The Persistent Exfiltration Threat
The researchers explained that the missing tenant ownership checks are the linchpin of the DifyTap attack. By configuring their own tracing for any application they can access as a client—which includes all publicly accessible applications—an attacker can set up a covert channel that funnels all data out of the platform. This is not a one-time data grab but a persistent interception capability that operates undetected until the trace configuration is manually audited.
Underlying Infrastructure Weakness: Outdated PDFium Library
Separately, Zafran discovered that Dify’s file parsing stack relied on a version of PDFium, an open-source C++ library for PDF rendering, that is vulnerable to CVE-2024-5846 (CVSS score: 8.8). This two-year-old use-after-free bug could allow a remote attacker to exploit heap corruption via a crafted PDF file. This finding underscores a common challenge in modern development: container images and dependencies can introduce visibility gaps that traditional vulnerability scanners fail to detect.
Patch Status and Recommendations
Following responsible disclosure, all vulnerabilities except CVE-2026-41948 have been addressed in Dify version 1.14.2, which was released last month. A fix for the remaining path traversal flaw is expected in the next release of the platform. Organizations running Dify should immediately update to version 1.14.2 and closely monitor for the upcoming patch.
What Affected Organizations Should Do Now
For any organization using Dify, the immediate action is to upgrade the platform to version 1.14.2 without delay. Administrators should also conduct a thorough audit of all trace configurations to ensure no unauthorized LLM tracing endpoints have been configured. It is also recommended to review user access logs for any unusual file preview activity, particularly for the /console/api/files/{file_id}/previewcodecodecode endpoint. Given the severity of the cross-tenant impact, it is vital to implement a multi-layer network segmentation solution to isolate sensitive data flows and ensure that internal APIs are not accessible from the public internet. Furthermore, organizations should deploy a robust file analysis and sandboxing solution for any uploaded documents to detect and block crafted PDFs that could exploit vulnerabilities like CVE-2024-5846. This layered approach is critical to protecting AI data in a landscape where supply chain and multi-tenant risks are rapidly evolving.