{"id":278723,"date":"2026-06-22T12:13:00","date_gmt":"2026-06-22T16:13:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/06\/22\/researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenants\/"},"modified":"2026-06-22T13:50:23","modified_gmt":"2026-06-22T17:50:23","slug":"researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenants","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/06\/22\/researchers-detail-difytap-flaws-in-dify-that-could-expose-ai-chats-across-tenants\/","title":{"rendered":"Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/researchers-detail-difytap-flaws-in.html\">Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/researchers-detail-difytap-flaws-in.html\">https:\/\/thehackernews.com\/2026\/06\/researchers-detail-difytap-flaws-in.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-22 12:13:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Jun 22, 2026<\/span><\/span><span class=\"p-tags\">AI Security \/ Vulnerability<\/span><\/p>\n<p>Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub stars, that could allow attackers to stealthily read artificial intelligence (AI) conversions from other customers&#8217; applications without requiring authentication.<\/p>\n<p>The vulnerabilities have been collectively codenamed DifyTap by Zafran Security.<\/p>\n<p>&#8220;Two were critical severity, two required no authentication, and three carried cross-tenant impact on Dify&#8217;s multi-tenant cloud service, allowing one customer&#8217;s data to be exposed to another,&#8221; researchers Ido Shani and Gal Zaban said.<\/p>\n<p>The security defects could have allowed attackers to read private AI chats from other customers&#8217; applications, creating a covert exfiltration channel for every message and model response.<\/p>\n<p>They also made it possible to traverse Dify&#8217;s internal Plugin Daemon API from unauthenticated requests and trigger cross-tenant internal API calls, as well as preview documents uploaded by other tenants and leak files across users within a tenant by attaching another user&#8217;s file unique identifier.<\/p>\n<p>Separately, Zafran said it also discovered that Dify&#8217;s file parsing stack relied on a version of PDFium, an open-source C++ library for PDF rendering, that was vulnerable to CVE-2024-5846 (CVSS score: 8.8), a two-year-old use-after-free bug that could allow a remote attacker to potentially exploit heap corruption via a crafted PDF file.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"601\" data-original-width=\"1117\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhOacqKBwVZPaGldSr42iMNW-FKKXfOZef4S84j3gcNraQeFnT78Iguthvl6n-9mYROWO6-R-PV3_2Ma4kpsroespVm1SrcTjw_OK_weSK8L1MEiMvib7fM-nr4RsAfseIYxCaq1yqfZROu-4-zNAHDMcVBtAcfeKtT_C9oltbKcfZqZgKR2fagLW5MLMsx\/s1600\/dify.png\"\/><\/p>\n<p>The remaining vulnerabilities are listed below &#8211;<\/p>\n<ul>\n<li>CVE-2026-41947 (CVSS score: 9.1) &#8211; An authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant ownership.<\/li>\n<li>CVE-2026-41948 (CVSS score: 9.4) &#8211; A path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon&#8217;s internal REST API by exploiting insufficient URL path&#8230;<\/li>\n<\/ul>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/06\/researchers-detail-difytap-flaws-in.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants https:\/\/thehackernews.com\/2026\/06\/researchers-detail-difytap-flaws-in.html Publish&#8230;<\/p>\n","protected":false},"author":1,"featured_media":278724,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjrjCumekV1hjkgdgebp4RqfYc_Yt9Swv4lG7ds3XMDHG9f-JxSuJSWY3UcWIoivJoJkJjdlBvtiQAHKy7NNgApCoD8ADtOpicXvKf9RJwAZT1DEGUkgX87bmSR8cO75Ss__mnLn8MyDEddnzhyphenhyphenRfcf_gWEtoLiKu53yXNQJtT0DP7nZufqBhB3P8VmvV48\/s1600\/dify.png","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,20,24,31,27],"class_list":["post-278723","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-artificial-intelligence","tag-cybersecurity","tag-exploit","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/278723"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=278723"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/278723\/revisions"}],"predecessor-version":[{"id":278725,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/278723\/revisions\/278725"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/278724"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=278723"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=278723"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=278723"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}