DifyTap: Four Unauthenticated Bugs in Dify Expose Cross-Tenant AI Conversations
Researchers at Zafran say a chain of flaws in the popular agentic workflow platform let attackers read other tenants' chats without logging in.

Key points
- Zafran Security has named a cluster of four Dify vulnerabilities DifyTap.
- An unauthenticated attacker can silently read AI conversations belonging to other tenants' applications.
- CVE identifiers and patched version numbers have not been confirmed in primary advisories at publication.
- Regulated operators should assess whether exposed prompt content triggers notification obligations under GDPR or the SEC's Item 1.05 Form 8-K rule.
- Operators of self-hosted Dify instances should restrict network access and pull conversation logs pending a confirmed patched build.
What exactly did researchers find?
Zafran Security has disclosed four vulnerabilities in Dify, the open-source agentic workflow platform with more than 146,000 GitHub stars. Chained together, the flaws let an unauthenticated attacker read AI conversations from another tenant's applications. No credentials are needed, and the victim's tenant is unlikely to produce the authentication anomalies that incident response teams typically hunt for. That passive read is what makes scoping any historical exposure genuinely difficult.
Public technical detail at disclosure is limited to that high-level behavior. CVE identifiers and patched release numbers haven't been confirmed in primary advisories this reporter could verify at publication. Operators should watch the project's GitHub security advisories feed at https://github.com/langgenius/dify/security/advisories for the authoritative fix details.
The 146,000-star reach of the repository is what gives this disclosure weight. It's among the most-watched AI orchestration projects in open source, and enterprise customers running multi-tenant deployments are the ones most directly exposed.
Should regulated operators be worried about notification obligations?
They should take a careful look, because the answer turns on what was in the prompts. AI conversation logs frequently contain personal data or customer records pasted by employees. Under GDPR, a confirmed unauthorized disclosure of personal data starts a notification clock to the lead supervisory authority. SEC registrants subject to the Item 1.05 Form 8-K cybersecurity disclosure rule, effective since December 2023, would need to assess materiality if Dify-hosted workflows touch financial reporting or significant customer data. CIRCIA reporting for covered entities remains pending final rulemaking at CISA, with the proposed rule published in the Federal Register on 4 April 2024 and the comment period closed.
The cross-tenant, no-authentication pattern here isn't new. Our coverage of the ServiceNow unauthenticated API exposure on 11 June 2026 raised the same notification question about whether enterprise customers would even know what got accessed.
What should you do right now?
Operators of self-hosted Dify should treat the instance as potentially exposed until they confirm a patched build, restrict network reachability of the admin and API surfaces, and review conversation access logs for unexpected source IPs. Managed customers should request a written statement from their provider on patch status and any indicators of cross-tenant access during the vulnerability window.
Threat Vectr will update this story as primary advisories, CVE assignments and vendor remediation guidance are published.



