# Critical DifyTap Vulnerabilities Expose AI Chats Across Dify Customers' Accounts
Cybersecurity researchers have disclosed a cluster of serious flaws in Dify, a popular open-source AI workflow platform with over 146,000 GitHub stars, that could allow attackers to silently harvest private AI conversations, documents, and application data from other customers without authentication. The vulnerabilities, collectively named DifyTap by Zafran Security, expose a fundamental architectural weakness in how Dify's multi-tenant cloud service enforces ownership and access controls.
## The Threat
Dify is widely used by organizations building AI agents and automating workflows—from customer service chatbots to internal knowledge assistants. As a multi-tenant platform, it handles sensitive data across thousands of independent customers. According to researchers Ido Shani and Gal Zaban, the disclosed flaws systematically undermined this isolation, allowing attackers to cross tenant boundaries and read private AI chats, preview uploaded documents, and even create persistent data exfiltration channels.
The most dangerous aspect: attackers don't need sophisticated tools or deep system knowledge. Two of the four vulnerabilities require no authentication at all, meaning an attacker only needs network access to Dify's application. An authenticated attacker—who can freely create a Dify account at no cost—gains the ability to enumerate and access data from *any* other customer's application, provided they know or guess the file ID or application identifier. One of the critical flaws allows an attacker to set up trace logging for any application they can access as a client, automatically forwarding all AI conversations to an attacker-controlled monitoring service. This creates a silent, persistent exfiltration channel that the victim would never detect unless they manually reviewed Dify's audit logs.
The impact extends beyond chat history. The vulnerabilities enable attackers to read document previews across tenants (up to 3,000 characters per file), traverse Dify's internal Plugin Daemon API to trigger cross-tenant API calls, and extract full file contents by supplying arbitrary file UUIDs. For organizations using Dify to build customer-facing AI products or process sensitive business documents, this represents a complete compromise of data isolation.
## Severity and Impact
| CVE ID | CVSS Score | CWE | Attack Vector | Authentication Required | Impact |
|---|---|---|---|---|---|
| CVE-2026-41947 | 9.1 | CWE-639 (Authorization Bypass) | Network / Adjacent | Yes (Editor role) | Configure trace for any application regardless of tenant ownership |
| CVE-2026-41948 | 9.4 | CWE-22 (Path Traversal) | Network / Adjacent | Yes | Access Plugin Daemon internal endpoints; cross-tenant API calls |
| CVE-2026-41949 | 7.5 | CWE-639 (Authorization Bypass) | Network / Adjacent | Yes | Read up to 3,000 characters of any file UUID across tenants |
| CVE-2026-41950 | 6.5 | CWE-639 (Authorization Bypass) | Network / Adjacent | Yes | Read full file contents by file UUID within tenant |
| CVE-2024-5846 (PDFium) | 8.8 | CWE-416 (Use-After-Free) | Network / Adjacent | No | Heap corruption via crafted PDF; RCE potential |
Criticality Notes:
## Affected Products
Dify:
The vulnerability disclosure does not specify which Dify deployment methods are affected (self-hosted Docker, cloud-hosted, Kubernetes), though the multi-tenant nature suggests the official Dify cloud service is the primary concern. Organizations running self-hosted Dify instances are likely affected by the same code paths.
## Mitigations
Immediate Actions:
1. Upgrade to version 1.14.2 immediately if you operate a Dify instance or use Dify's cloud service. This patches four of the five disclosed vulnerabilities.
2. Monitor audit logs for suspicious activity, particularly:
- Unexpected trace configurations added to your applications
- File preview or chat message access from unfamiliar source IPs
- Unauthorized API calls to internal Plugin Daemon endpoints
3. Restrict application access to Dify applications that contain sensitive data:
- Do not expose production AI applications publicly unless necessary
- Use IP whitelisting or authentication layers in front of Dify if possible
- Consider running a self-hosted instance with restricted network access
4. Rotate credentials and tokens if you suspect your instance was accessed during the vulnerable period:
- Reset API keys used by integrations
- Audit third-party trace providers or logging services connected to your applications
5. Disable file uploads for sensitive document types until CVE-2026-41948 is resolved, or implement a pre-upload file scanning and sanitization process.
6. Watch for the next Dify release addressing CVE-2026-41948 (path traversal). Plan an immediate upgrade once available.
Long-Term Recommendations:
## References
---
## HackWire Analysis
DifyTap exposes a critical problem in the AI platform rush: multi-tenant architecture is hard, and many projects treat authorization as an afterthought. Dify has 146,000 GitHub stars—it's become infrastructure for thousands of organizations building AI products—yet basic tenant isolation failed. The fact that an unauthenticated attacker can trigger the PDFium RCE, and that attackers can freely register accounts to exfiltrate data from competitors' applications, suggests these weren't edge cases or subtle race conditions. These were design-level oversights.
The timing matters. As enterprises move sensitive workflows to AI platforms, they're inheriting these same isolation gaps. A customer service bot using Dify now has an undetected exfiltration vector pointed at an attacker-controlled logging service. A medical clinic using Dify to build a patient intake agent could leak protected health information to a competitor with a free trial account.
What's particularly troubling is the persistence angle: CVE-2026-41947 lets attackers *configure trace providers* on victim applications. That's not a one-time read—it's a tap that runs continuously, forwarding every message forever, until someone manually audits application settings. Most organizations don't review those settings regularly.
The two-year-old PDFium vulnerability still being present suggests Dify's dependency management and container image scanning have gaps. Tools exist to detect these, but they require discipline. As container adoption explodes and security tools proliferate, the gap between *knowing* a vulnerability exists and *actually fixing it* in deployed images remains disturbingly wide.
For defenders: if you're using Dify in production, upgrade today. If you're evaluating AI platforms, ask about multi-tenant testing, static analysis practices, and vulnerability disclosure processes. The platforms that are transparent about security flaws are often the ones investing in finding them.
— HackWire Editorial
## Related Coverage