kokumօtօ[verified]@__kokumotoPatch
The article reports cross‑tenant data leakage vulnerabilities in DifyTap, with most CVEs fixed in version 1.14.2; CVE‑2026‑41948 remains unpatched.
solemsli[verified]@N_aBo_Disclosure
The post announces new CVEs (2026-41948/49/50), summarizing their technical aspects and impact without detailing exploitation or fixes.
CVE@CVEnewDisclosure
CVE‑2026‑41950 is disclosed as an authorization bypass in Dify prior to v1.14.0 that lets authenticated users read other users’ uploaded file contents. No PoC, exploit code, or patch information is provided.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE-2026-41950, describing an authorization bypass in Dify versions prior to 1.14.0 that permits unauthorized file access, without providing PoC, exploit code, or evidence of active exploitation.
Infoflowcloud@infoflowcloudDisclosure
An alert reports CVE-2026-41950, an authorization bypass in Dify before v1.14.0 that allows authenticated users to read other users' uploaded files; no PoC, patch, or active exploitation details are provided.