Close Menu
    What's Hot

    Live Updates: Montreal Manhunt Ends After Shootout That Killed Police Officer

    Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach

    Home Depot: Demand Still Needs To Do More (NYSE:HD)

    Facebook X (Twitter) Instagram
    Trending
    • Live Updates: Montreal Manhunt Ends After Shootout That Killed Police Officer
    • Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach
    • Home Depot: Demand Still Needs To Do More (NYSE:HD)
    • The Open: Former Premier League stars Jimmy Bullard and Peter Odemwingie fall short in bid to qualify for men’s golf major | Golf News
    • Lionel Messi breaks World Cup goals record with 17th strike
    • ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack
    • Traveling with Sleep Apnea: Expert Recommendations for…
    • Vance Claims Progress in First Day of Iran Talks
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

    adminBy adminJune 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 22, 2026AI Security / Vulnerability

    Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

    Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers’ applications without requiring authentication.

    The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.

    “Two were critical severity, two required no authentication, and three carried cross-tenant impact on Dify’s multi-tenant cloud service, allowing one customer’s data to be exposed to another,” researchers Ido Shani and Gal Zaban said.

    The security defects could have allowed attackers to read private AI chats from other customers’ applications, creating a covert exfiltration channel for every message and model response.

    Cybersecurity

    They also made it possible to traverse Dify’s internal Plugin Daemon API from unauthenticated requests and trigger cross-tenant internal API calls, as well as preview documents uploaded by other tenants and leak files across users within a tenant by attaching another user’s file unique identifier.

    Separately, Zafran said it also discovered that Dify’s file parsing stack relied on a version of PDFium, an open-source C++ library for PDF rendering, that was vulnerable to CVE-2024-5846 (CVSS score: 8.8), a two-year-old use-after-free bug that could allow a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    The remaining vulnerabilities are listed below –

    • CVE-2026-41947 (CVSS score: 9.1) – An authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership.
    • CVE-2026-41948 (CVSS score: 9.4) – A path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon’s internal REST API by exploiting insufficient URL path sanitization and access internal, private endpoints.
    • CVE-2026-41949 (CVSS score: 7.5/5.9) – An authorization bypass vulnerability in the file preview endpoint (“/console/api/files/{file_id}/preview”) that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file’s UUID.
    • CVE-2026-41950 (CVSS score: 6.5) – An authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request.

    The missing tenant ownership checks can be exploited to redirect all messages and responses from victim applications to an attacker-controlled LLM trace provider. It’s worth noting that anyone can freely register for a Dify account.

    Cybersecurity

    “Consequently, an attacker can configure their own tracing for any application they can access as a client, which includes all publicly accessible applications,” the researchers explained. “This allows an attacker to create a persistent exfiltration channel for all messages and responses sent in the application.”

    Following responsible disclosure, all vulnerabilities barring CVE-2026-41948 have been addressed in version 1.14.2, which was shipped last month. A fix for the pending flaw is expected to be made available in the next release of Dify.

    “DifyTap demonstrates where the challenge lies in vulnerability visibility, particularly in container images, where differences between deployments can create visibility gaps that traditional scanners cannot detect,” the company said.

    chats detail Dify DifyTap expose Flaws Researchers Tenants
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhatsApp gets new chief as Meta taps India’s CRED founder Kunal Shah, and invests $900M in startup
    Next Article OpenAI Launches Full-Scale Effort to Patch Open Source Bugs as It Takes on Anthropic’s Mythos
    admin
    • Website

    Related Posts

    ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

    June 22, 2026

    29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

    June 22, 2026

    Stop Your Legacy Infrastructure from Hijacking Your AI Agents

    June 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Live Updates: Montreal Manhunt Ends After Shootout That Killed Police Officer

    Tata Electronics, a major tech supplier to Apple and Tesla, confirms data breach

    Home Depot: Demand Still Needs To Do More (NYSE:HD)

    The Open: Former Premier League stars Jimmy Bullard and Peter Odemwingie fall short in bid to qualify for men’s golf major | Golf News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by