Threat · curated 27 Jun 2026
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
First reported thehackernews.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Cross-tenant exposure of AI chats in a widely used agentic workflow platform could leak sensitive data from any organization relying on Dify.
Researchers at Zafran Security disclosed four vulnerabilities, collectively codenamed DifyTap, in the open-source agentic workflow platform Dify that could allow unauthenticated attackers to stealthily read AI conversations from other customers' applications across tenants.