info@news-matic.com

details

4 vulnerabilities in Dify expose cross-tenant data

The most severe flaw, CVE-2026-41947, resides in Dify's tracing system, enabling attackers to create a persistent channel for exfiltrating all messages and responses from any accessible application without authentication. June 23, 2026 Four vulnerabilities, collectively named DifyTap, have been discovered in the open-source AI platform Dify, which is utilized by major companies to run over a million applications across more than 60 industries. Two of these vulnerabili... [1874 chars]

ADVERTISEMENT

Cookie Consent + Tracking