HomeSecurityResearchers uncover DifyTap vulnerabilities in Dify that expose AI customer conversations

Researchers uncover DifyTap vulnerabilities in Dify that expose AI customer conversations

Cybersecurity researchers have revealed details of four vulnerabilities in Dify, an open-source workflow platform with more than 146,000 stars on GitHub. These vulnerabilities could allow attackers to secretly read artificial intelligence (AI) conversations from other customer applications without requiring authentication. The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.

See also: Photographer Lev Mazaraki Names 6 Technologies That Revolutionized Photography

Article Image: Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Two were critical, two did not require authentication, and three affected multiple customers in Dify’s multi-tenant cloud service, allowing the exposure of one customer’s data to another,” researchers Ido Shani and Gal Zaban.

The security flaws could have allowed attackers to read private AI conversations from other client applications by creating a hidden export channel for each model message and response. They also made it possible to access Plugin Daemon from unauthenticated requests and trigger internal API calls between clients, as well as preview documents uploaded by other clients and leak files between users within a client by attaching another user's unique file identifier.

Additionally, Zafran discovered that Dify's file analysis system was based on a version of PDFium, an C++ library for PDF rendering, that was vulnerable to CVE-2024-5846 (CVSS score: 8.8), a Use After Free bug that could allow a remote attacker to potentially exploit memory corruption via a malicious PDF file.

CVE -2026-41947 (CVSS score: 9.1) is an authorization override vulnerability that allows authenticated processing users to define and enable detection configurations for any application regardless of customer ownership.

CVE -2026-41948 (CVSS score: 9.4) is a path vulnerability that allows authenticated users to handle requests forwarded to the Plugin Daemon's internal REST API by exploiting inadequate URL path sanitization and accessing internal, private endpoints.

See also: Researchers uncover service providers fueling PBaaS scams

Researchers uncover DifyTap vulnerabilities in Dify that expose AI customer conversations

CVE -2026-41949 (CVSS score: 7.5/5.9) is an authorization override vulnerability in the file preview point (“/console/api/files/{file_id}/preview”) that allows any authenticated user to read up to 3,000 characters of any uploaded document across all clients and workspaces using only the file’s UUID.

CVE -2026-41950 (CVSS score: 6.5) is an authorization override vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same client by providing an arbitrary file UUID in the file table of a chat message request.

Deficiencies in client ownership checks can be exploited to redirect all messages and responses from victim applications to an LLM detection provider controlled by the attacker. It is worth noting that anyone can freely sign up for a Dify account.

Therefore, an attacker can configure their own trace for any application they can access as a client, which includes all publicly accessible applications,” the researchers explained. “This allows an attacker to create a persistent export channel for all messages and responses sent to the application.

Following responsible disclosure, all vulnerabilities except CVE-2026-41948 have been addressed in version 1.14.2, which was released last month. A fix for the pending flaw is expected to be available in the next release of Dify.

See also: Does AI produce more original ideas than researchers?

Researchers uncover DifyTap vulnerabilities in Dify that expose AI customer conversations

DifyTap shows where the challenge lies in vulnerability visibility, particularly in container images, where differences between deployments can create visibility gaps that traditional scanners cannot detect,” the company said.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS