Dify Security Update Advisory

Dify Security Update Advisory

Overview


A security update addressing vulnerabilities in Dify has been released. Users of this product should update to the latest version.

Affected Products


  • CVE-2026-41947, CVE-2026-41948, CVE-2026-41949: Dify version 1.14.1 Or earlier.
  • CVE-2026-41950: Dify version 1.14.0 Or earlier.

Resolved Vulnerabilities


  • Authentication bypass vulnerability in Dify (CVE-2026-41947).
  • Path traversal vulnerability in Dify (CVE-2026-41948).
  • Authentication bypass vulnerability in Dify (CVE-2026-41949).
  • Authentication bypass vulnerability in Dify (CVE-2026-41950).

Response Information


Vulnerability Patches have been provided via the latest update. The recommended patch versions are as follows:

  • CVE-2026-41947, CVE-2026-41949: Dify version 1.14.2 Or higher.
  • CVE-2026-41948: Apply the patch according to the instructions on the reference site.
  • CVE-2026-41950: Dify version 1.14.0 Or later.