CVE Tools

CVE-2026-41948

Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access

No known exploitation. EPSS puts it in the 79th percentile. Only a workaround so far.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build is published yet. The vendor describes a workaround.

Steps

Written by AI from the record
  1. Check whether you are running dify version 1.14.1 or earlier.
  2. Confirm whether the Plugin Daemon / plugin internal API endpoints are enabled and reachable from your users or networks.
  3. Review who has access to your Dify instance (especially any users who could reach the affected API routes).
  4. Apply the fix referenced by the Dify project (upgrade per the vendor’s release notes that include the referenced pull request).
  5. Until you can upgrade, restrict network access to Dify (especially the Plugin Daemon and any internal/admin-style endpoints) so only trusted networks/users can reach them.

What it is

From the CVE record

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker.

In plain language

Written by AI from the record

CVE-2026-41948 is a path-traversal flaw in Dify v1.14.1 and earlier that can let an attacker use a specially crafted request to reach internal Dify features; it’s mainly a risk if someone already has an account in your Dify setup, so you should update and restrict access.

In dify (CVE-2026-41948), a path traversal issue (CWE-23) in the Plugin Daemon internal API routing allows crafted URL paths to escape tenant-scoped paths and access internal endpoints by insufficient URL path sanitization; exploitation requires no special user interaction and does not require authentication according to the core finding, but the patch guidance indicates tenant/route access is part of the trigger conditions.

If you're affected

  • Internal feature or debug access
  • Cross-tenant data exposure
  • System manipulation from tenant
  • Service disruption risk

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS79th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

1.9% chance of exploitation activity in the next 30 days, which ranks it in the 79th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Attention now

unknown.

Real risk signals with little public attention so far.

Lifecycle

12 events over 129 days, from the signal feeds we watch.

  1. EPSS band changemoderate → lowepss band change
  2. EPSS band changelow → moderate
  3. EPSS band changelow → moderate
  4. EPSS band changelow → moderateepss band change, nuclei check added
  5. Workaround availablerecord updated
  6. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Scored 9.4 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability LowReduced performance or intermittent disruption of service

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Dify, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store