DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Security researchers at Zafran discovered four vulnerabilities in Dify, a popular open source AI application platform, collectively dubbed 'DifyTap.' The flaws include a tracing hijack (CVE-2026-41947, CVSS 9.1) that lets attackers silently intercept AI chat histories by registering a rogue tracing backend, a Plugin Daemon path traversal (CVE-2026-41948, CVSS 9.4) exposing internal APIs to unauthenticated requests, and two UUID-based document access bugs (CVE-2026-41949 and CVE-2026-41950, both CVSS 6.5) enabling cross-tenant file exposure. Three of the four CVEs are patched in Dify 1.14.2; a fix for CVE-2026-41948 is available on GitHub. No real-world exploitation has been observed yet. Organizations are advised to patch promptly, apply WAF rules for CVE-2026-41948, and treat AI platforms as critical enterprise systems.