Threat · curated 27 Jun 2026

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Coverage timeline

22 Jun 2026thehackernews.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Cross-tenant exposure of AI chats in a widely used agentic workflow platform could leak sensitive data from any organization relying on Dify.

Researchers at Zafran Security disclosed four vulnerabilities, collectively codenamed DifyTap, in the open-source agentic workflow platform Dify that could allow unauthenticated attackers to stealthily read AI conversations from other customers' applications across tenants.