kokumօtօ[verified]@__kokumotoPatch
The post lists several CVEs for DifyTap, notes one remains unpatched while others were resolved in v1.14.2, and highlights a tenant‑crossing data leak without providing exploitation details.
solemsli[verified]@N_aBo_Disclosure
Three newly disclosed CVEs (CVE-2026-41949, CVE-2026-41950, CVE-2026-41948) are presented with their high‑severity capabilities: cross‑tenant document preview via UUID, intra‑tenant file read, and a path traversal reaching internal APIs, underscoring the need for immediate remediation.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
The analysis reveals that attackers exploited authorization bypasses in Dify’s multi‑tenant platform, exposing private conversations across tenants; no patch information is provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The post announces an authorization bypass vulnerability (CVE‑2026‑41949) in Dify 1.14.1’s File Preview Endpoint, linking to a vulnerability database, but gives no details on patches, exploitation, or PoC.