Dify patches four CVEs that could expose private chats and files across tenants in its AI app platform

Dify fixed four security flaws that could let attackers on shared cloud instances read other customers’ AI chats, preview uploaded documents, and reach internal APIs. The issues are CVE-2026-41947, CVE-2026-41948, CVE-2026-41949, and CVE-2026-41950, affecting multi-tenant Dify deployments; Zafran said a low-bar console account could abuse tracing and plugin-daemon features for cross-tenant access, and Dify released fixes in version 1.14.2. The report also notes Dify used a PDFium build vulnerable to CVE-2024-5846 until December 21, 2025.
Why it matters: Organizations using Dify, especially in shared cloud setups, may have exposed private prompts, responses, and uploaded files to other users. Admins should update to Dify 1.14.2 immediately and apply any recommended web application firewall rules for CVE-2026-41948.

Sources

Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
Ionut Arghire 2026.06.23 100% relevant
This article appears to be the first tracked report establishing the DifyTap vulnerability cluster as a distinct event, with named CVEs, attack paths, and the vendor's fixed version.
← Back to all stories