Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps

https://www.securityweek.com/wp-content/uploads/2025/05/AI-Hallucinations.jpg

Four vulnerabilities in the open source AI platform Dify could be exploited to siphon other tenants’ data in multi-tenant cloud configurations, Zafran Security warns.

A highly popular LLMOps platform for creating, deploying, maintaining, and monitoring AI applications, Dify powers over 1 million applications across more than 50 industries.

Called DifyTap, the newly uncovered security defects in the platform allowed attackers to read private chats from other customers’ applications, trigger cross-tenant internal API calls, preview documents uploaded by other tenants, and leak other users’ files within the same tenant.

Tracked as CVE-2026-41947 (CVSS score of 9.1), the first issue existed in Dify’s tracing functionality, which supports profiling and monitoring AI applications.

Because the endpoints relevant to configuring tracing did not validate the sender’s tenant, attackers could send requests for any application hosted on the instance. Exploitation requires a Dify console user, which is available to anyone signing up for the...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more