Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants
Researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform, that could allow attackers to read AI conversations from other customers' applications. The vulnerabilities have been collectively codenamed DifyTap.
Intelligence analysis by Llama 3.3 70B

The DifyTap flaws could allow attackers to stealthily read artificial intelligence conversations from other customers' applications without requiring authentication, creating a covert exfiltration channel for every message and model response.
Imagine you're having a private conversation with a friend, but someone is secretly listening in. That's what these vulnerabilities could allow to happen with AI conversations on a platform called Dify.
Analysis
Introduction to DifyTap Flaws
The DifyTap flaws are a set of four vulnerabilities discovered in Dify, an open-source agentic workflow platform. These vulnerabilities could allow attackers to read AI conversations from other customers' applications, creating a covert exfiltration channel for every message and model response. The flaws were collectively codenamed DifyTap by Zafran Security.
Technical Details of the Vulnerabilities
The vulnerabilities include an authorization bypass vulnerability, a path traversal vulnerability, and two other authorization bypass vulnerabilities. These flaws could be exploited to redirect all messages and responses from victim applications to an attacker-controlled LLM trace provider. The fact that anyone can freely register for a Dify account makes it easier for attackers to configure their own tracing for any application they can access as a client.
Implications of the DifyTap Flaws
The DifyTap flaws have significant implications for the security of AI-powered applications. The fact that the flaws could be exploited without authentication makes them particularly concerning. The vulnerabilities highlight the need for robust security measures to protect sensitive data, including AI conversations. The discovery of the DifyTap flaws also underscores the importance of responsible disclosure and prompt patching of vulnerabilities to prevent exploitation by attackers.
Key points
- Four vulnerabilities discovered in Dify, an open-source agentic workflow platform
- Vulnerabilities could allow attackers to read AI conversations from other customers' applications
- Flaws could be exploited without authentication
- Discovery of vulnerabilities highlights the need for robust security measures
The discovery of the DifyTap flaws and the subsequent patching of the vulnerabilities demonstrate the importance of responsible disclosure and collaboration between security researchers and vendors. This cooperation can help prevent the exploitation of vulnerabilities and protect sensitive data.
The existence of the DifyTap flaws highlights the potential risks associated with AI-powered applications and the need for robust security measures to protect sensitive data. If left unaddressed, these vulnerabilities could be exploited by attackers, compromising the security and privacy of users.



