More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Dify, an open source LLMOps platform powering over 1 million AI apps across 50+ industries, has four serious security flaws that let attackers pull data from other tenants in multi-tenant cloud setups. Zafran Security labels these defects DifyTap. The worst one, CVE-2026-41947 (CVSS 9.1), lives in Dify’s tracing feature. Because the tracing API doesn’t check tenant IDs, any signed-up user can hook into any publicly accessible application, capture its messages and responses, and maintain a persistent exfiltration channel.
A second critical bug, CVE-2026-41948 (CVSS 9.4), hits the plugin daemon that manages Dify plugins. Two exposed primitives allow arbitrary GET and POST calls, enabling path traversal, stealing other tenants’ plugin icons, or manipulating their environments. The remaining two flaws, CVE-2026-41949 and CVE-2026-41950, mismanage file IDs and permissions. Attackers could preview or download documents uploaded by other tenants or by users within the same tenant.
Beyond DifyTap, Zafran found the PDF preview endpoint relied on an old Chromium PDFium binary (version 126.0.6462.0) vulnerable to CVE-2024-5846, a use-after-free bug disclosed in June 2024. All issues were fixed in Dify version 1.14.2, released December 21, 2025. Users should upgrade immediately and add WAF rules against CVE-2026-41948.
Questions about this article
No questions yet.