The Dify AI platform, which supports over 1 million applications, has been found to have four serious vulnerabilities that could expose sensitive data across its multi-tenant cloud environment, according to Zafran Security. These flaws, assigned CVEs 2026-41947 through 2026-41950, allow attackers to access private chats, trigger unauthorized internal API calls, and retrieve files from other users, creating significant risks for data leakage. In response, Dify released version 1.14.2 with patches for these issues, and users are advised to implement specific web application firewall rules alongside the update to enhance security.

Dify: Dify is an open source LLMOps platform for creating, deploying, maintaining, and monitoring AI applications. It supports multi-tenant cloud configurations where different users share infrastructure. The platform is the subject of recently disclosed vulnerabilities that could expose data across tenants.
Zafran Security: Zafran Security is a cybersecurity firm specializing in vulnerability research and threat analysis for software platforms. The company identified and disclosed four high-severity flaws in Dify that enable cross-tenant data access and exfiltration. Their findings include detailed exploit paths and recommendations for users to apply patches and protective rules.

`json
{
“Patch Availability”: “An updated release of Dify has been made available to resolve identified security flaws.”,
“Mitigation Guidance”: “Users should apply the software update and implement specific web application firewall rules to counteract threats.”,
“Vulnerability Disclosure”: “Four CVEs correspond to vulnerabilities in Dify’s tracing, plugin daemon, and file handling components.”
}
`