216.73.216.233

CVE-2026-41948

· Published 18/05/2026 15:16 · Modified 19/05/2026 19:25

Labels: CVE-2026-41948 2026-05-18CVE-2026-41948CWE-23[email protected]

Essential information

Published
18/05/2026 15:16
Modified
19/05/2026 19:25
Author
Creator
CVSS
9.2 CRITICAL (v3) 9.2 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
dify / dify cpe:2.3:a:dify:dify:*:*:*:*:*:*:*:*

References