CVE-2026-41948 Details
Description
Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
A path traversal vulnerability has been identified in Dify versions through 1.14.1. This vulnerability allows authenticated users to manipulate requests sent to the Plugin Daemon's internal REST API by taking advantage of inadequate URL path sanitization. Attackers can escape their authorized tenant path using unencoded dot sequences in task identifiers or altered filename parameters, accessing internal endpoints such as debug interfaces. Exploitation requires only knowledge of the victim tenant's UUID. Notably, Dify Cloud permits unauthenticated self-registration, making it easy for attackers to create accounts.
Users can update to Dify version 1.14.2 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dify dify | <= 1.14.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 18, 2026 | New CVE Received | [email protected] |