Researchers disclosed four vulnerabilities in the open-source AI application platform Dify that could let attackers silently access sensitive customer data, including private AI chat histories and uploaded files. The issues, collectively named DifyTap by Zafran Security, affected tracing configuration, the internal Plugin Daemon API, document preview authorization, and cross-file user access. Two of the flaws were rated critical, and some attack paths were unauthenticated, creating cross-tenant exposure risks in Dify's multi-tenant cloud service.
The vulnerabilities could enable persistent interception and exfiltration of AI conversations, abuse of Dify's internal plugin services, preview of uploaded documents from other tenants, and access to files belonging to other users in the same tenant. Zafran said Dify is widely deployed, citing more than 10 million API image pulls and tens of thousands of internet-facing instances. Dify patched three issues in version 1.14.2, while CVE-2026-41948 remained pending at disclosure, with a fix merged on GitHub and additional mitigation available through targeted WAF rules; researchers also noted Dify's file parsing stack included vulnerable PDFium code affected by CVE-2024-5846.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers publicly detailed the four DifyTap vulnerabilities, describing how they could enable persistent interception of AI chat messages and unauthorized access to uploaded documents and files. Zafran said it was not aware of real-world exploitation at the time of reporting.
Dify fixed all disclosed issues except CVE-2026-41948 in version 1.14.2, which the source says was released last month. The remaining flaw was not yet patched in that release.
Zafran Security identified four vulnerabilities in the Dify open-source AI workflow platform that could expose AI chats, uploaded documents, and files across users and tenants. The issues included unauthenticated attack paths, Plugin Daemon abuse, document preview authorization bypass, and cross-file access weaknesses.
For the remaining DifyTap flaw, CVE-2026-41948, a fix had been merged on GitHub by the time of reporting. Users still on version 1.14.2 could mitigate exposure with targeted WAF rules until the next release.
Until 2025-12-21, Dify's PDF preview capability relied on a Chromium PDFium binary affected by CVE-2024-5846, according to Zafran. The reference indicates this dependency issue ended on that date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourcesecurityweek.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.