# Dify's DifyTap Vulnerabilities Expose Millions of AI Chat Histories to Silent Exfiltration
## The Threat
Researchers at security vendor Zafran have uncovered a critical vulnerability cluster—collectively branded "DifyTap"—affecting Dify, an open-source orchestration platform that has become central infrastructure for thousands of organizations deploying AI applications at scale. The four vulnerabilities allow unauthenticated and authenticated attackers to silently access, exfiltrate, and manipulate sensitive data flowing through Dify instances, including private AI conversation histories, internal documents, and cross-tenant files.
Dify serves as a no-code/low-code abstraction layer for AI application management, allowing organizations to build, deploy, and maintain generative AI systems without developing custom infrastructure from scratch. The platform's popularity is staggering: it has exceeded 10 million Docker image pulls and Zafran identified tens of thousands of internet-facing Dify instances exposed to the public internet. This massive installed base means the DifyTap vulnerabilities potentially affect tens of thousands of organizations and millions of end users whose conversations with AI applications are stored and accessed through compromised Dify deployments.
The vulnerability chain fundamentally undermines the confidentiality and integrity assumptions organizations make when deploying Dify. Attackers can "wiretap" AI chat histories—a fitting metaphor that captures how these bugs enable passive, ongoing surveillance of sensitive conversations—while remaining virtually undetected. Combined with path traversal, document preview, and cross-tenant file access flaws, DifyTap transforms Dify from a trusted orchestration layer into a potential data exfiltration pipeline.
## Severity and Impact
| CVE ID | CVSS Score | Severity | Attack Vector | Attack Complexity | Authentication | Key Impact |
|--------|-----------|----------|---|---|---|---|
| CVE-2026-41947 | 9.1 | Critical | Network | Low | Low | Tracing hijack; enables wiretapping of AI chat histories |
| CVE-2026-41948 | 9.4 | Critical | Network | Low | None | Plugin Daemon path traversal; unauthenticated access to internal APIs |
| CVE-2026-41949 | 6.5 | Medium | Network | Low | None | Unauthorized document preview; cross-tenant document access |
| CVE-2026-41950 | 6.5 | Medium | Network | Low | Low | Cross-user file access within same tenant; lateral data leakage |
CWE Classifications:
## Affected Products
Dify Versions:
## Mitigations
Organizations operating Dify deployments should take immediate action:
1. Upgrade to Dify 1.14.2 or Later — This stable release patches three of the four vulnerabilities (CVE-2026-41947, CVE-2026-41949, CVE-2026-41950). Plan and execute this upgrade as a priority.
2. Deploy Custom GitHub Build for CVE-2026-41948 — Organizations unable to wait for the next stable release should build and deploy the latest version directly from GitHub, which includes the merged patch for the Plugin Daemon path traversal flaw (CVE-2026-41948).
3. Implement Web Application Firewall (WAF) Rules — For instances running version 1.14.2 pending a full rebuild, Zafran recommends deploying WAF rules specifically designed to block exploitation attempts against CVE-2026-41948. Work with your WAF vendor or consult Zafran's advisory for rule signatures.
4. Assume Compromise and Conduct Forensics — Organizations with internet-facing Dify instances running vulnerable versions should assume potential unauthorized access has occurred. Review access logs, audit trail data, and conversation histories for signs of tampering or exfiltration. Document findings for incident response and regulatory notification purposes.
5. Network Segmentation and Access Controls — Restrict network access to Dify instances through a reverse proxy or network firewall. Limit internet-facing exposure; Dify should ideally be accessible only to authorized clients and internal services, not the public internet.
6. Monitor for Exploitation Indicators — Watch for unusual spikes in API requests to /tracer, /plugin, /documents, or file preview endpoints, as well as unexpected cross-tenant data access patterns in audit logs.
## References
---
## HackWire Analysis
The DifyTap disclosures expose a critical blind spot in enterprise AI architecture: most organizations treating orchestration platforms like Dify as trusted, secure infrastructure with minimal threat modeling. The reality is starker. These platforms sit at the intersection of all sensitive data flows—user inputs, API keys, conversation histories, document uploads—making them extraordinarily high-value targets. A single compromised Dify instance can leak months of proprietary AI interactions, customer service transcripts, and internal documents in one sweep.
What makes DifyTap particularly concerning is the attack profile. Unlike traditional RCE bugs requiring active exploitation, the tracing hijack (CVE-2026-41947) enables *passive surveillance*. An attacker gains read access to conversation histories without triggering alerts or leaving obvious audit trail indicators. In regulated industries—healthcare, finance, legal—this creates compliance nightmares: organizations may be unable to detect when sensitive data has been exfiltrated, complicating breach notification timelines and regulatory disclosure obligations.
The second worry signal: Dify's installed base. With tens of thousands of internet-facing instances and 10 million+ API pulls, this vulnerability affects real-world deployments at scale. Early reconnaissance suggests many organizations are still running versions 1.14.1 and earlier, suggesting patch adoption will lag. For defenders, this creates a window where attackers can continue harvesting data from unpatched systems for weeks or months after the advisory.
The positive: all patches are available or merged, and WAF mitigation rules provide a temporary bridge. Organizations moving fast can patch this week. But this incident underscores a broader pattern: as AI platforms mature and centralize, their security maturity often lags deployment velocity. Treat orchestration platforms with the same threat model as your databases.
— *HackWire Editorial*
---
## Related Coverage