connect24h[verified]@connect24hDisclosure
The post announces four CVE‑2026‑41947 to 41950 vulnerabilities affecting the Dify platform, notes their high severity (CVSS 9.1‑9.4), and calls for immediate mitigation while awaiting vendor patches.
kokumօtօ[verified]@__kokumotoPatch
The post identifies a group of DifyTap vulnerabilities (CVE‑2024‑5846, CVE‑2026‑41947‑41950), notes that CVE‑2026‑41948 remains unpatched, while the remaining issues are fixed in version 1.14.2.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post announces two critical CVEs (CVE-2026-41947, CVE-2026-41948) affecting Dify versions up to 1.14.1, describing authorization bypass and path‑traversal weaknesses that may expose sensitive tenant data across boundaries.
solemsli[verified]@N_aBo_Disclosure
The post announces CVE-2026-41947, a high‑severity flaw that allows cross‑tenant data interception via unverified tracing endpoints.
Aseem Shrey[verified]@AseemShreyDisclosure
The post highlights a severe tenancy‑validation flaw in a tracing system, allowing any authenticated editor to silently intercept all messages and model responses across the instance. It focuses on the vulnerability’s details without mentioning a PoC, patch, or active exploitation evidence.
z3n[verified]@zench4nDisclosure
The post announces two new CVEs in Dify, detailing authorization bypass and path traversal flaws that could compromise orchestration platforms.
z3n[verified]@zench4nDisclosure
The post announces that Dify 1.14.1 contains two CVEs—a 2026-41947 authorization bypass and a 2026-41948 path traversal—that can be weaponized by AI agents, potentially allowing full system compromise.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The content announces CVE-2026-41947 as an authorization bypass in Dify 1.14.1, providing a brief description but no PoC, exploit, patch, or evidence of active use.