Home / Jun 23, 2026 / Story
0
#9 The Hacker News general June 22, 2026 at 16:13 UTC

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

By [email protected] (The Hacker News)

AI Summary

Zafran Security disclosed four vulnerabilities collectively named 'DifyTap' in Dify, an open-source AI agentic workflow platform with over 146,000 GitHub stars, that allow unauthenticated attackers to read AI conversation data across tenant boundaries. The cross-tenant data leakage flaws expose sensitive AI interaction logs from other customers' applications, making this a critical concern for multi-tenant Dify deployments used in enterprise AI workflows. Organizations running Dify should apply available patches and audit their multi-tenant configurations immediately.

Relevance score: 75.0/100

# More from June 23