logo

Data Exposure Flaws in Dify AI Platform Put 1 Million+ App Tenants at Risk

ID: 61c0b113-d822-5540-98f0-cda0613ae0cd

STIX ID: report--61c0b113-d822-5540-98f0-cda0613ae0cd

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

Security researchers disclosed multiple multi-tenant isolation vulnerabilities in Dify's cloud-hosted AI platform that permitted authenticated tenants to access other tenants' private conversation histories, preview uploaded documents, and reach internal APIs. The root cause is a failure to enforce tenant-scoped authorization combined with predictable identifiers and insufficient isolation; organizations using Dify SaaS should assume potential exposure until patches are applied and follow recommended mitigations (apply patches, audit uploaded data, rotate API keys, consider self-hosting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.