Impact
A path traversal flaw in Dify v1.14.1 and earlier allows authenticated users to manipulate requests forwarded to the Plugin Daemon’s internal REST API by using unencoded dot sequences in task identifiers or manipulated filename parameters. The insufficient URL path sanitization lets an attacker traverse outside the authorized tenant directory, access internal endpoints such as debug interfaces, and read or interact with data belonging to other tenants. The weakness is a classic example of CWE‑23, improper path validation.
Affected Systems
All installations of Dify version 1.14.1 or older, including the cloud offering by langgenius, are vulnerable. The issue appears across the open‑source and self‑hosted product, as identified by the relevant CPE strings for dify and langgenius: dify:dify and langgenius:dify.
Risk and Exploitability
The flaw carries a CVSS score of 9.3, indicating very high severity. An EPSS score of 2% suggests that the vulnerability is likely to be exploited more frequently than many others. It is not currently listed in the CISA KEV catalog. Although the flaw requires an authenticated user, the Dify Cloud permits unauthenticated free registration, enabling attackers to quickly create an account, obtain a tenant UUID, and exploit the path traversal without additional tooling. This combination of high severity, reasonable exploitation likelihood, and ease of access makes the risk a high‑priority concern for any multi‑tenant deployment.
OpenCVE Enrichment