{"id":57985,"date":"2026-06-23T13:25:47","date_gmt":"2026-06-23T17:25:47","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=57985"},"modified":"2026-06-23T13:25:47","modified_gmt":"2026-06-23T17:25:47","slug":"dify-ai-vulnerabilities-data-exposure","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/dify-ai-vulnerabilities-data-exposure\/","title":{"rendered":"Dify AI Platform Exposes Data of 1 Million Apps via Four Flaws"},"content":{"rendered":"<p>Four unpatched vulnerabilities in the open-source artificial intelligence platform <a href=\"https:\/\/dify.ai\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Dify<\/a> could allow attackers to silently exfiltrate sensitive data from other tenants in multi-tenant cloud configurations, exposing more than one million AI applications to potential compromise. Discovered by researchers at <a href=\"https:\/\/www.zafran.io\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Zafran Security<\/a> and collectively named <a href=\"https:\/\/overcentral.com\/en\/difytap-flaws-ai-chats-tenants\/\" title=\"DifyTap Flaws Expose AI Chats Across Tenants\" data-iacss-internal=\"1\">DifyTap<\/a>, the flaws enable a range of cross-tenant attacks, including the reading of private chat messages, unauthorized API calls, and the theft of uploaded documents and files.<\/p>\n<h2>What Is Dify and Why These Vulnerabilities Matter<\/h2>\n<p>Dify is a popular LLMOps platform used to build, deploy, and monitor <a href=\"https:\/\/overcentral.com\/en\/ai-worm-autonomous-spread-cybersecurity\/\" title=\"AI-Powered Worms Wreak Havoc by Spreading Autonomously\" data-iacss-internal=\"1\">AI-powered<\/a> applications. It supports over one million applications across more than 50 industries, making it a high-value target for attackers seeking access to sensitive conversational data, proprietary business logic, and user-uploaded content. The DifyTap vulnerabilities are particularly dangerous because they require only a valid console user account \u2014 available to anyone who registers on the platform \u2014 and can be exploited without any administrative privileges.<\/p>\n<h2>Breakdown of the Four DifyTap Flaws<\/h2>\n<h3>CVE-2026-41947 \u2014 Tracing Feature Allows Persistent Data Exfiltration (CVSS 9.1)<\/h3>\n<p>The most critical flaw resides in Dify&#8217;s tracing functionality, which is designed to help developers profile and monitor their AI applications. The relevant API endpoints failed to validate the sender&#8217;s tenant association, meaning an attacker could send requests to configure tracing for any application hosted on the same Dify instance. Once tracing is enabled on a target application, the attacker gains a persistent channel to intercept every message and response flowing through that application. Because the exploit works against any publicly accessible application, the potential scope of data leakage is massive.<\/p>\n<h3>CVE-2026-41948 \u2014 Plugin Daemon Enables Cross-Tenant API Calls (CVSS 9.4)<\/h3>\n<p>The second vulnerability affects the plugin daemon responsible for managing and executing Dify plugins. Two separate primitives within the daemon give attackers the ability to make arbitrary GET and POST requests to any API endpoint. These primitives can be chained with path-traversal techniques to access plugin icons belonging to other tenants or to manipulate settings in other tenants&#8217; environments. The CVSS score of 9.4 reflects the ease of exploitation and the severe confidentiality and integrity impact.<\/p>\n<h3>CVE-2026-41949 and CVE-2026-41950 \u2014 File Handling Flaws Leak User Data<\/h3>\n<p>The remaining two vulnerabilities are rated high severity and concern Dify&#8217;s file identification and access permission mechanisms. CVE-2026-41949 allows an attacker to preview files uploaded by other tenants without proper authorization, while CVE-2026-41950 enables the retrieval of files uploaded by other users within the same tenant environment. Together, these flaws undermine the multi-tenant isolation that cloud-hosted Dify deployments depend on.<\/p>\n<h2>Additional Risk: Outdated PDF Parsing Library<\/h2>\n<p>Zafran also identified that for approximately 18 months \u2014 until December 21, 2025 \u2014 the PDF preview endpoint in Dify relied on Chromium PDFium binary version 126.0.6462.0, which is susceptible to CVE-2024-5846, a use-after-free vulnerability disclosed in <a href=\"https:\/\/overcentral.com\/en\/nintendo-switch-2-star-fox-june-games\/\" title=\"Nintendo Switch 2 gets Star Fox and more major games in June\" data-iacss-internal=\"1\">June<\/a> 2024. While this issue was not directly exploited in the DifyTap chain, it represents an additional attack surface in environments where the PDF preview feature is enabled.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>Dify released version 1.14.2, which includes patches for all four DifyTap vulnerabilities. Any organization running a self-hosted Dify instance or using a multi-tenant cloud deployment should update to this version immediately. In addition to patching, administrators should deploy web application firewall (WAF) rules specifically designed to mitigate exploitation attempts targeting CVE-2026-41948. For organizations using a managed Dify cloud service, confirm with the provider that the patched version has been deployed and that tenant isolation has been verified. Users who interact with Dify-powered applications should be aware that their chat histories and uploaded files may have been exposed; changing passwords and enabling multi-factor authentication on any accounts linked to those applications is a prudent precaution. As a broader security measure, organizations running AI platforms should implement a robust endpoint protection solution with behavioral analysis capabilities to detect anomalous API calls and data-access patterns that may indicate a cross-tenant breach.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Four unpatched vulnerabilities in the open-source artificial intelligence platform Dify could allow attackers to silently exfiltrate sensitive data from other tenants in multi-tenant cloud configurations, exposing more than one million AI applications to potential compromise. Discovered by researchers at Zafran Security and collectively named DifyTap, the flaws enable a range of cross-tenant attacks, including the [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74047,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CTL40TN.jpg","fifu_image_alt":"Dify AI Platform Exposes Data of 1 Million Apps via Four Flaws","footnotes":""},"categories":[349],"tags":[],"class_list":["post-57985","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CTL40TN.jpg","fifu_image_alt":"Dify AI Platform Exposes Data of 1 Million Apps via Four Flaws","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57985","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=57985"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/57985\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74047"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=57985"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=57985"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=57985"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}