DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
ID: b5a93137-83b4-59ab-9782-579394eb9e3b
STIX ID: report--b5a93137-83b4-59ab-9782-579394eb9e3b
Feed Name: GBHackers
Threat Score
The report details multiple critical vulnerabilities in the widely used Dify LLMOps platform (including CVE-2026-41947 and CVE-2026-41948) that enable silent exfiltration of AI prompts/responses, unauthenticated access to internal services via path traversal, and unauthorized file previews across tenants; patches have been released and mitigations (WAF rules, Snort signatures, updates) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
