Researchers from Zafran Security have identified 'DifyTap,' a suite of four vulnerabilities within the Dify open-source AI orchestration platform. These flaws, including CVE-2026-41947, CVE-2026-0343, and CVE-2025-56520, enable unauthenticated attackers to bypass tenant isolation via the orchestration layer. By exploiting the platform's tracing system, attackers can establish persistent, stealthy channels for the exfiltration of AI-generated responses, user conversations, and tenant-specific documents. This vulnerability poses a systemic risk to over 1 million AI applications across 60+ industries, allowing for large-scale, cross-tenant data leakage and unauthorized access to sensitive AI-driven workflows and proprietary datasets.
- Vulnerability Overview
- Identification of the 'DifyTap' vulnerability suite by Zafran Security researchers.
- Targeting of the Dify open-source AI orchestration framework and its multi-tenant architecture.
- Primary threat vectors include cross-tenant data exposure and unauthenticated access.
- Vulnerability Mechanics: The Tracing Vector
- Exploitation of the Dify Tracing System to circumvent existing authentication protocols.
- Establishment of persistent, stealthy exfiltration channels for real-time data capture.
- Unauthorized interception of AI-generated content, user prompts, and conversational metadata.
- Capability to access tenant-specific documents and proprietary datasets stored within the platform.
- Impact and Exploitation Status
- Potential compromise of over 1 million AI-driven applications globally.
- Broad systemic reach impacting more than 60 diverse industrial sectors.
- High-severity risk to enterprise-grade multi-tenant isolation and data privacy.
- Exposure of highly sensitive conversational intelligence and private corporate documentation.
- Detection and Mitigation
- Immediate application of security patches for identified CVEs to the Dify orchestration layer.
- Rigorous auditing of Dify Tracing System configurations and permission models.
- Implementation of egress monitoring to identify anomalous, persistent outbound communication.
- Continuous validation of tenant separation integrity within AI-orchestrated environments.
Related posts
- helpnetsecurity.com — F5 launches AI Security Platform to uncover and secure shadow AI
- feeds.feedburner.com — Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
- gbhackers.com — DifyTap Flaws Expose AI Data Across Tenants on Platform Powering 1M+ Apps
- Security Affairs — DifyTap: Four Bugs Put over 1 million AI Apps at Risk
- SC Media — 4 vulnerabilities in Dify expose cross-tenant data
- Techjacksolutions
- Aiweekly
- Mallory
- Develeap
- Develeap
- Github
- Github
- Crowdsec
- Purpleshieldsecurity
- SecurityWeek — Data Exposure Flaws Threaten Dify AI Platform Used by 1 Million Apps
- Dark Reading — DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories