Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Zafran Security disclosed four vulnerabilities in Dify, a widely deployed open-source platform used to build and operate AI agent workflows, that together allow attackers to read AI conversations across organizational tenant boundaries, access internal APIs, and exfiltrate uploaded documents with minimal authentication. Two of the four individual CVEs carry critical CVSS scores (9.1 and 9.4 per vendor disclosure); the aggregate item-level CVSS base is 7.5 (high). Three of the four flaws affect Dify’s cloud service with cross-tenant impact. Organizations running Dify in production, particularly in multi-tenant or cloud-hosted configurations, face direct risk of AI conversation data theft and unauthorized document exfiltration until v1.14.2 is applied.

Author

Tech Jacks Solutions