Dify Security Update Advisory
Overview
A security update addressing vulnerabilities in Dify has been released. Users of this product should update to the latest version.
Affected Products
- CVE-2026-41947, CVE-2026-41948, CVE-2026-41949: Dify version 1.14.1 Or earlier.
- CVE-2026-41950: Dify version 1.14.0 Or earlier.
Resolved Vulnerabilities
- Authentication bypass vulnerability in Dify (CVE-2026-41947).
- Path traversal vulnerability in Dify (CVE-2026-41948).
- Authentication bypass vulnerability in Dify (CVE-2026-41949).
- Authentication bypass vulnerability in Dify (CVE-2026-41950).
Response Information
Vulnerability Patches have been provided via the latest update. The recommended patch versions are as follows:
- CVE-2026-41947, CVE-2026-41949: Dify version 1.14.2 Or higher.
- CVE-2026-41948: Apply the patch according to the instructions on the reference site.
- CVE-2026-41950: Dify version 1.14.0 Or later.