1 link tagged with all of: ai-security + multitenancy + vulnerability-management + dify + data-exposure
Links
Four high-severity flaws in the open-source Dify platform allow authenticated users to read private chats, preview documents, and leak files across tenants by abusing tracing endpoints, plugin daemon APIs, and flawed file permissions. One issue also stems from a vulnerable PDFium version (CVE-2024-5846). Dify 1.14.2 patches these bugs; operators should update immediately and apply WAF rules for CVE-2026-41948.
- Four "DifyTap" flaws in Dify (used by 1M+ AI apps) let authenticated users cross tenant boundaries to read private chats, steal files, and hijack plugin data.
- Worst bug (CVE-2026-41947, CVSS 9.1) abuses the tracing API's missing tenant checks to create a persistent exfiltration channel from any public app.
- Plugin daemon flaw (CVE-2026-41948, CVSS 9.4) allows arbitrary GET/POST calls enabling path traversal and cross-tenant plugin manipulation.
- All issues, plus an outdated PDFium library vulnerable to CVE-2024-5846, are fixed in Dify 1.14.2—upgrade immediately and apply WAF rules for CVE-2026-41948.
dify
multitenancy
data-exposure
ai-security
vulnerability-management