FILTERING BY: CLEAR FILTER

Dify AI Platform: 'DifyTap' Vulnerabilities Enable Cross-Tenant Data Exfiltration

Researchers from Zafran Security have identified 'DifyTap,' a suite of four vulnerabilities within the Dify open-source AI orchestration platform. These flaws, including CVE-2026-41947, CVE-2026-0343, and CVE-2025-56520, enable unauthenticated attackers to bypass tenant isolation via the orchestration layer. By exploiting the platform's tracing system, attackers can establish persistent, stealthy channels for the exfiltration of AI-generated responses, user conversations, and tenant-specific documents. This vulnerability poses a systemic risk to over 1 million AI applications across 60+ industries, allowing for large-scale, cross-tenant data leakage and unauthorized access to sensitive AI-driven workflows and proprietary datasets.


LINK COPIED TO CLIPBOARD