Dify vulnerabilities named DifyTap allowed attackers to read private chats, preview private documents, and access internal APIs.

Four DifyTap flaws could expose private AI chats and files across Dify tenants; three are fixed in version 1.14.2.

Four vulnerabilities allow attackers to exploit Dify, a platform for AI application building and management, to silently access sensitive data.