Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-41948: Dify versions 1.14.1 and prior allow attackers to access internal data
CVE-2026-41948
Summary
Dify versions 1.14.1 and prior have a security flaw that allows attackers to access internal data they shouldn't be able to see. This happens because the software doesn't properly check URLs, making it possible for attackers to navigate to sensitive areas. To fix this, update to the latest version of Dify.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| dify | dify |
<= 1.14.1 cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:* |
Original title
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insuffic...
Original description
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
nvd CVSS3.1
7.7
nvd CVSS4.0
9.2
Vulnerability type
CWE-23
Published: 18 May 2026 · Updated: 28 May 2026 · First seen: 18 May 2026