Dify flaws expose cross-tenant AI data, Zafran says
What happened
Security researchers disclosed four vulnerabilities in the open‑source AI platform Dify, including multiple cross‑tenant issues that could expose other tenants' files and internal APIs. Several issues are patched and one fix has been merged but awaits release, making the immediate operational task inventory and mitigation across hosted and vendor instances. Watch for the next release and hosted‑service advisories; unpatched vendor‑hosted instances represent the highest immediate risk to buyers
Why the category manager should care
Treat the disclosure as a supply‑chain security event: insist on vendor evidence of patch deployment, mitigations, and a supplier IR playbook before buying services that depend on Dify
Key facts
- Multiple cross‑tenant vulnerabilities disclosed
- Patches applied for most issues; one fix merged and pending release
- Platform widely used to build production AI applications