Vulnerability Intelligence Report
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
CVE-2026-41948
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
Nuclei Template
CVSS Base Score
9.3
CRITICAL
EPSS Probability:0.51%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-23 ↗Relative Path Traversal
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| langgenius | dify | 0 <= 1.14.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VulnCheck · Bug Bounty Provider · USA |
| Reserved | 2026-04-22T18:50:43 |
| Published | 2026-05-18T13:50:21 |
| Patch Date | 2026-03-30 |
| Last Updated | 2026-07-14T20:01:01 |
Community Chatter & Buzz