DifyTap: Four Critical CVEs in Dify Let Attackers Silently Wiretap AI Chat Histories Across 1M+ Apps
If your team is running Dify — the open-source LLM workflow platform behind over a million apps — you need to patch now. Researchers from Zafran Security have disclosed four vulnerabilities collectively named DifyTap that allow authenticated attackers to silently intercept AI chat conversations across tenant boundaries. The most severe carries a CVSS score of 9.4. This story is a few weeks old (disclosed June 22), but it’s critical enough to cover regardless: tens of thousands of internet-facing Dify instances remain unpatched, and the platform is embedded in enterprise workflows at companies like Volvo and Maersk. ...