Description
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
Published: 2026-05-18
Score: 9.3 Critical
EPSS: 1.9% Low
KEV: No
Impact: Data Disclosure
Action: Patch Now
AI Analysis

Impact

A path traversal flaw in Dify v1.14.1 and earlier allows authenticated users to manipulate requests forwarded to the Plugin Daemon’s internal REST API by using unencoded dot sequences in task identifiers or manipulated filename parameters. The insufficient URL path sanitization lets an attacker traverse outside the authorized tenant directory, access internal endpoints such as debug interfaces, and read or interact with data belonging to other tenants. The weakness is a classic example of CWE‑23, improper path validation.

Affected Systems

All installations of Dify version 1.14.1 or older, including the cloud offering by langgenius, are vulnerable. The issue appears across the open‑source and self‑hosted product, as identified by the relevant CPE strings for dify and langgenius: dify:dify and langgenius:dify.

Risk and Exploitability

The flaw carries a CVSS score of 9.3, indicating very high severity. An EPSS score of 2% suggests that the vulnerability is likely to be exploited more frequently than many others. It is not currently listed in the CISA KEV catalog. Although the flaw requires an authenticated user, the Dify Cloud permits unauthenticated free registration, enabling attackers to quickly create an account, obtain a tenant UUID, and exploit the path traversal without additional tooling. This combination of high severity, reasonable exploitation likelihood, and ease of access makes the risk a high‑priority concern for any multi‑tenant deployment.

Generated by OpenCVE AI on September 24, 2026 at 22:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dify to a release that resolves the path traversal bug.
  • Enhance the Plugin Daemon’s internal API with strict input validation, rejecting unencoded dot sequences and ensuring all requested paths remain within the tenant’s base directory.
  • Restrict or disable exposed debug and internal endpoints so that only privileged admins can access them.

Generated by OpenCVE AI on September 24, 2026 at 22:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:langgenius:dify:*:*:*:*:*:node.js:*:*

Mon, 22 Jun 2026 17:30:00 +0000


Tue, 26 May 2026 17:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Tue, 19 May 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Dify
Dify dify
CPEs cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:*
Vendors & Products Dify
Dify dify

Mon, 18 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 May 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Langgenius
Langgenius dify
Vendors & Products Langgenius
Langgenius dify

Mon, 18 May 2026 14:30:00 +0000

Type Values Removed Values Added
Description Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
Title Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
Weaknesses CWE-23
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-14T20:01:01.518Z

Reserved: 2026-04-22T18:50:43.622Z

Link: CVE-2026-41948

cve-icon Vulnrichment

Updated: 2026-05-18T14:38:50.530Z

cve-icon NVD

Status : Modified

Published: 2026-05-18T15:16:25.977

Modified: 2026-06-22T18:16:37.033

Link: CVE-2026-41948

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T22:30:17Z

Weaknesses
  • CWE-23

    Relative Path Traversal