Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access and exfiltrate sensitive data.
June 22, 2026
A new set of bugs in a popular AI building platform could allow attackers to effectively wiretap vulnerable customers.
Researchers with security vendor Zafran discovered a series of four vulnerabilities in Dify, an open source AI platform that acts as a kind of orchestration layer to help organizations create, deploy, and manage AI applications without needing to build out the infrastructure themselves. Dify is exceedingly popular; it has more than 10 million pulls of its API image on Docket, and Zafran identified tens of thousands of internet-facing Dify instances.
The set of vulnerabilities, referred to cumulatively as "DifyTap," includes tracing configuration flaw CVE-2026-41947 (CVSS 9.1); Plugin Daemon path traversal vulnerability CVE-2026-41948 (CVSS 9.4); unauthorized document preview bug CVE-2026-41949 (CVSS 6.5); and cross-file user access flaw CVE-2026-41950 (CVSS 6.5).







