DifyTap AI Vulnerabilities
Abstract
The DifyTap research disclosed by Zafran Labs in June 2026 exposes four vulnerabilities in Dify, a widely deployed open-source AI platform, two of which are rated critical and two of which require no authentication. The flaws allow attackers to silently intercept AI conversation data across organizational boundaries, traverse internal APIs without credentials, and access documents and files belonging to other tenants, all without sophisticated tooling or elevated access. The platform's file parsing stack also carried a known memory corruption CVE for over 18 months undetected, and standard container scanning tools failed to surface any of these vulnerabilities due to a structural gap in how AI application layers are assessed. These findings are not isolated to Dify; they represent a repeating risk pattern across third-party AI and LLM platforms where rapid adoption has outpaced security rigor, and any enterprise running AI workflow tools, chatbots, or LLM Ops platforms sourced from third-party vendors is carrying vendor risk that requires active governance.