logo

DifyTap Flaws Allow Attackers to Wiretap AI Data Across Tenants – 1M+ Apps Impacted

ID: e65e3a37-3edd-5d94-9569-0a641d9a2cf2

STIX ID: report--e65e3a37-3edd-5d94-9569-0a641d9a2cf2

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

Author: Abinaya

...
...

Multiple critical vulnerabilities in the Dify AI platform (notably CVE-2026-41947 and CVE-2026-41948) can enable cross-tenant data exposure—allowing attackers to enable tracing to capture full chat histories, exploit Plugin Daemon path traversal to access unauthenticated internal APIs, and preview or retrieve files across tenants; an outdated PDFium use-after-free (CVE-2024-5846) in production increases risk from malicious uploads. Zafran identified tens of thousands of internet-facing Dify instances and the vendor has released fixes (1.14.2 for several CVEs, with an additional patch merged), recommending immediate upgrades, WAF rules, monitoring of plugin/file endpoints, and limiting public exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.