solemsli[verified]@N_aBo_Patch
The message advises upgrading to Dify 1.15.0 to patch CVE-2026-41948 or applying WAF rules if upgrading is not possible.
kokumօtօ[verified]@__kokumotoPatch
Researchers disclosed DifyTap flaws with several CVEs; all but CVE‑2026‑41948 are fixed in v1.14.2, leaving one unpatched vulnerability.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The post discloses that Dify versions 1.14.1 and earlier suffer from critical authorization bypass and path‑traversal vulnerabilities that could allow authenticated attackers to access internal endpoints and redirect application traces across tenants, potentially exposing sensitive data.
solemsli[verified]@N_aBo_Disclosure
The post announces multiple high‑severity CVEs, detailing how they enable cross‑tenant document preview, file reading, and internal API access via path traversal, but provides no PoC, exploit code, patches, or active exploitation evidence.
Aseem Shrey[verified]@AseemShreyGeneral
Dify has patched most reported vulnerabilities, but CVE-2026-41948—a path traversal flaw—remains unfixed; the post provides minimal detail and no exploit or patch information.
Aseem Shrey[verified]@AseemShreyDisclosure
The post announces a newly disclosed high‑severity path traversal vulnerability (CVE-2026-41948) in Dify’s plugin icon endpoint, detailing how it allows unauthenticated access to internal APIs.
z3n[verified]@zench4nGeneral
The excerpt identifies two CVEs in Dify and notes that they involve an authorization bypass and a path traversal, but does not provide further technical detail, PoC, or evidence of exploitation or mitigation.
z3n[verified]@zench4nDisclosure
The post announces two newly disclosed CVEs (CVE-2026-41947 and CVE-2026-41948) affecting Dify 1.14.1, describing an authorization bypass and a path traversal flaw that could lead to full system compromise.