Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.2epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview endpoint with an intercepted file UUID to extract sensitive content from documents without ownership or workspace permission verification. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
langgenius · difypublic PoCs found — 2
cve_referencehuntr.com/bounties/d50a0240-7951-4939-b989-9bded66c7682unverifiedcve_referencewww.zafran.io/resources/difytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-appsunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://github.com/langgenius/dify/commit/432a6412a3fdb30ce48003d699b90cc7d890df20https://github.com/langgenius/dify/pull/35797https://github.com/langgenius/dify/releases/tag/1.14.2https://huntr.com/bounties/d50a0240-7951-4939-b989-9bded66c7682https://www.vulncheck.com/advisories/dify-authorization-bypass-via-file-preview-endpointhttps://www.zafran.io/resources/difytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps