CVE-2026-41948Disclosure(dify / dify)

HIGHCVSS 9.4 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch dify dify systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dify

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 8d ago at 2 mentions (2026-05-18); latest day: 1
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
dify

Deep dive

Activity timeline12 mentions / 9d
01122Mentions · 2026-05-18: 2Mentions · 2026-05-19: 1Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-06-23: 1Mentions · 2026-07-02: 2Mentions · 2026-07-06: 2Mentions · 2026-07-24: 1Mentions · 2026-09-15: 1PoC Mentioned / Linked · 2026-07-24: 1PoC Mentioned / Linked · 2026-09-15: 1Exploit Tool / Code · 2026-07-24: 1Active Exploitation · 2026-05-19: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-05-18: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-23: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-06: 1Technical Details · 2026-09-15: 105-1805-1905-2005-2106-2307-0207-0607-2409-15
Signal classification5 categories
Disclosure
541.7%
General
216.7%
Patch
216.7%
PoC
216.7%
Active Exploitation
18.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-182
Disclosure2
2026-05-191
Active Exploitation1
2026-05-201
Disclosure1
2026-05-211
General1
2026-06-231
Patch1
2026-07-022
Disclosure1General1
2026-07-062
Disclosure1Patch1
2026-07-241
PoC1
2026-09-151
PoC1
Full discourse12 posts
  • pdnuclei-bot@pdnuclei_bot
    PoC

    🚨 CVE-2026-41948 - critical 🚨 Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal > Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in th... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-41948 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE-2026-41948, a critical unauthenticated path traversal in Dify <=1.14.1, and primarily shares a Nuclei template (PoC) for detection via the ProjectDiscovery library.

    010132511
    1.3K followersView on X
  • solemsli@N_aBo_
    Patch

    6/ Fix: upgrade Dify to 1.15.0. If you're stuck on 1.14.2, add WAF rules for CVE-2026-41948.

    Post summary

    The message advises upgrading to Dify 1.15.0 to patch CVE-2026-41948 or applying WAF rules if upgrading is not possible.

    10010119
    19 followersView on X
  • kokumօtօ@__kokumoto
    Patch

    Difyでテナント跨ぎでデータが漏洩する脆弱性群DifyTapについて。CVE-2024-5846、CVE-2026-41947、CVE-2026-41948、CVE-2026-41949、CVE-2026-41950。CVE-2026-41948は未修正。それ以外はバージョン1.14.2で修正。 https://thehackernews.com/2026/06/researchers-detail-difytap-flaws-in.html?m=1

    Post summary

    Researchers disclosed DifyTap flaws with several CVEs; all but CVE‑2026‑41948 are fixed in v1.14.2, leaving one unpatched vulnerability.

    00020898
    7.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Critical - Multiple Dify Vulnerabilities (CVE-2026-41947, CVE-2026-41948) Dify <= 1.14.1 is affected by critical authorization bypass and path traversal vulnerabilities that could allow authenticated attackers to access internal plugin daemon endpoints and redirect application traces from victim tenants to attacker-controlled providers. The issues impact multi-tenant isolation and may expose sensitive application prompts, messages, and responses across tenant boundaries. 👉 Affected: Dify <= 1.14.1

    Post summary

    The post discloses that Dify versions 1.14.1 and earlier suffer from critical authorization bypass and path‑traversal vulnerabilities that could allow authenticated attackers to access internal endpoints and redirect application traces across tenants, potentially exposing sensitive data.

    0002083
    196 followersView on X
  • solemsli@N_aBo_
    Disclosure

    4/ It goes further. CVE-2026-41949 lets you preview documents uploaded by other tenants with nothing but a file UUID. CVE-2026-41950 lets users read files uploaded by other users inside the same tenant. CVE-2026-41948 (CVSS 9.4) is a Plugin Daemon path traversal that can reach internal APIs.

    Post summary

    The post announces multiple high‑severity CVEs, detailing how they enable cross‑tenant document preview, file reading, and internal API access via path traversal, but provides no PoC, exploit code, patches, or active exploitation evidence.

    1000055
    19 followersView on X
  • Aseem Shrey@AseemShrey
    General

    Dify patched most of these in v1.14.2. But CVE-2026-41948 (the path traversal) is still waiting on a fix. This is the AI agent security problem I keep talking about. We're building multi-tenant AI platforms with the same auth bugs we've been finding in web apps for 20 years. The attack surface changed. The mistakes didn't. Credit: Zafran Security researchers Ido Shani and Gal Zaban https://securityaffairs.com/194081/hacking/difytap-four-bugs-put-over-1-million-ai-apps-at-risk.html

    Post summary

    Dify has patched most reported vulnerabilities, but CVE-2026-41948—a path traversal flaw—remains unfixed; the post provides minimal detail and no exploit or patch information.

    10000152
    8.7K followersView on X
  • Aseem Shrey@AseemShrey
    Disclosure

    Dify is an open-source agentic AI platform. 146K GitHub stars. Used across 50+ industries. The worst bug (CVE-2026-41948, CVSS 9.4): path traversal in the plugin icon endpoint. The filename parameter gets injected straight into an internal URL with zero sanitization. Result: unauthenticated access to Dify's internal Plugin Daemon API. Game over.

    Post summary

    The post announces a newly disclosed high‑severity path traversal vulnerability (CVE-2026-41948) in Dify’s plugin icon endpoint, detailing how it allows unauthenticated access to internal APIs.

    10000267
    8.7K followersView on X
  • z3n@zench4n
    General

    Recent vulnerabilities highlight the risk. CVE-2026-41947 and CVE-2026-41948 in Dify show how authorization bypass and path traversal can compromise orchestration platforms.

    Post summary

    The excerpt identifies two CVEs in Dify and notes that they involve an authorization bypass and a path traversal, but does not provide further technical detail, PoC, or evidence of exploitation or mitigation.

    1000037
    1.4K followersView on X
  • z3n@zench4n
    Disclosure

    Take Dify 1.14.1 as an example. CVE-2026-41947 demonstrates an authorization bypass, while CVE-2026-41948 shows how path traversal can be weaponized. When AI agents interact with local file systems or backend APIs, these flaws lead to full system compromise.

    Post summary

    The post announces two newly disclosed CVEs (CVE-2026-41947 and CVE-2026-41948) affecting Dify 1.14.1, describing an authorization bypass and a path traversal flaw that could lead to full system compromise.

    100005
    1.4K followersView on X
  • M0oris@pwdnx1337
    PoC

    CVE-2026-41940 &amp; CVE-2026-41948 — cPanel &amp; WHM Auth Bypass https://github.com/AnotherSec/Cpanel https://t.co/95dbCosOHp

    Post summary

    The tweet highlights cPanel/WHM authentication bypass CVEs and links to a GitHub repository that likely hosts proof‑of‑concept code for exploitation.

    00000100
    1 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Some increased actor activities are shown targeting langgenius dify (CVE-2026-41948) https://vuldb.com/vuln/364479/cti

    Post summary

    The statement notes increased attacker activity targeting langgenius dify (CVE‑2026‑41948), indicating likely active exploitation, although no specific technical or patch information is provided.

    0000078
    2.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41948 Path Traversal in Dify Versions 1.14.1 and Prior via Insufficient URL Sanitization https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41948

    Post summary

    The text announces CVE‑2026‑41948 as a path‑traversal flaw in Dify 1.14.1 and earlier, citing insufficient URL sanitization, but offers no proof of concept, exploit code, or patch details.

    0000058
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdifydify---

Explore more