DifyTap: Vulnerabilities in Dify Can Expose AI Chats Across Tenants

Colleagues — a cybersecurity alert: Zafran Security disclosed DifyTap — four vulnerabilities in Dify allowing unauthenticated access to other customers' AI chats.
Key points:
- Two vulnerabilities are critical; three have cross‑tenant impact — enabling stealthy exfiltration of messages and model responses.
- Affected components: Plugin Daemon API, file preview, and PDF parsing (vulnerable PDFium).
- CVEs: CVE‑2026‑41947/41948/41949/41950 and CVE‑2024‑5846.
Why it matters: anyone can register on Dify and configure tracing to create an exfiltration channel.
Recommendation: upgrade to Dify 1.14.2 and monitor patches. How do you plan to respond to similar threats?
#cybersecurity #cloudsecurity #AIsecurity #vulnerability

