1 link tagged with all of: dify + vulnerability-management + data-exposure + ai-security + multitenancy
Links
Four high-severity flaws in the open-source Dify platform allow authenticated users to read private chats, preview documents, and leak files across tenants by abusing tracing endpoints, plugin daemon APIs, and flawed file permissions. One issue also stems from a vulnerable PDFium version (CVE-2024-5846). Dify 1.14.2 patches these bugs; operators should update immediately and apply WAF rules for CVE-2026-41948.
dify
multitenancy
data-exposure
ai-security
vulnerability-management