Skip to main content
QUIETLYTIC
Vulnerability

Dify Path Traversal (CVE-2026-41948)

CVE-2026-41948 is a CVSS 9.4 path traversal flaw in Dify allowing cross-tenant access to internal debug endpoints, reported exploited by VulnCheck.

CVE-2026-41948
Threat Level
CRITICAL
CVSS
9.4
Status
Active Exploitation
Confidence
Medium
Affected Products
Dify, Dify (1.14.1 and prior)

CVE-2026-41948 carries a CVSS 3.1 base score of 9.4 against Dify, an open-source platform for building and hosting AI/LLM applications, including a hosted multi-tenant offering, Dify Cloud. NVD classifies it as CWE-23 (Relative Path Traversal) and states the flaw affects version 1.14.1 and prior. VulnCheck’s KEV feed reports the CVE as exploited, dated September 1, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-41948 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states the flaw allows requests forwarded to Dify’s internal Plugin Daemon REST API to be manipulated through insufficient URL path sanitization. An attacker can use unencoded dot-sequence path traversal in task identifiers or manipulated filename parameters to escape their own authorized tenant’s path and reach internal endpoints, including debug interfaces, in a different tenant’s space. NVD states this requires only knowledge of the victim tenant’s UUID.

One phrasing detail matters here: NVD’s description says this is exploitable by “authenticated users,” while the CVSS vector’s PR:N component indicates no privileges are required at the API-request level. NVD’s own note resolves that apparent tension directly: Dify Cloud allows free, unauthenticated self-registration, so “authenticated” in practice means nothing more than having created a free account — a step NVD itself calls “trivially accessible to any attacker.” We report both facts rather than collapse them into a single simplified claim, since the distinction matters for understanding what “authenticated” means in this specific context.

Evidence and confidence

  • Medium confidence — the CVSS 9.4 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L), the CWE-23 classification, the affected-version ceiling (1.14.1), and the full cross-tenant traversal mechanism all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.14453, a 96.4th percentile score as of our ingestion, one of the higher scores in our recent coverage.

No field is in conflict between our two sources. Our data carries no fixed-version field beyond NVD’s stated affected ceiling.

Why this matters

This is a multi-tenant isolation failure, a category of bug that’s especially serious for any hosted platform where customers share infrastructure but expect their data walled off from one another. NVD’s description frames the real-world stakes plainly: this is not merely a theoretical boundary crossing but a path to internal debug interfaces in another customer’s tenant space, on a platform NVD’s own referenced research describes as powering roughly one million downstream applications. A successful attacker needs only a free Dify Cloud account and a target tenant’s UUID — not a sophisticated exploit chain — to potentially access another organization’s AI application internals.

Because Dify underlies applications built by other organizations, the practical blast radius of a breach here extends past Dify’s own operator to every downstream application and its own users and data, a dependency relationship that may not be obvious to those downstream users at all.

Frequently Asked Questions

What is CVE-2026-41948? A CVSS 9.4 relative path traversal vulnerability (CWE-23) in Dify, an AI/LLM application platform, affecting version 1.14.1 and prior, allowing cross-tenant access to internal Plugin Daemon debug endpoints given a victim tenant’s UUID.

Is CVE-2026-41948 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 1, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Do I need to be a paying customer or have special access to exploit this? No. NVD’s own note states Dify Cloud allows free, unauthenticated self-registration, making account creation trivially accessible to any attacker — “authenticated” here means only having a free account.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our data carries no fixed-version field. NVD states version 1.14.1 and prior are affected; confirm directly with Dify’s own release notes whether a later version addresses this specific CVE.


Severity, vector, weakness classification, and the full cross-tenant traversal mechanism sourced from the National Vulnerability Database record for CVE-2026-41948, which references Dify’s own GitHub pull request and independent security research from Zafran. Exploitation status and the September 1, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools