Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
ID: a261a443-2b96-5c0d-8465-44e6b8da1d87
STIX ID: report--a261a443-2b96-5c0d-8465-44e6b8da1d87
Feed Name: The Hacker News
Threat Score
Researchers disclosed “DifyTap,” a set of four vulnerabilities in the open-source Dify agentic workflow platform that enable authorization bypasses and path traversal to read other tenants' AI conversations and uploaded files (CVE-2026-41947–41950), alongside a vulnerable PDFium dependency; most issues have been patched in v1.14.2 except one pending fix, and the flaws could be used to create persistent exfiltration channels because anyone can register an account.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
