PT-2026-41676 · Dify · Dify
-Lan-
+2
·
Published
2026-05-18
·
Updated
2026-05-18
·
CVE-2026-41949
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Dify versions prior to 1.14.1
Description
An authorization bypass exists in the file preview endpoint, allowing any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces. An attacker can use an intercepted file UUID to access the "/console/api/files/{file id}/preview" endpoint and extract sensitive content without ownership or workspace permission verification. Dify Cloud facilitates this by allowing unauthenticated free self-registration, making account creation easily accessible.
Recommendations
Update to a version later than 1.14.1.
As a temporary workaround, restrict access to the "/console/api/files/{file id}/preview" endpoint to minimize the risk of unauthorized document access.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dify