PT-2026-41676 · Dify · Dify
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Dify versions prior to 1.14.2
Description
An authorization bypass exists in the file preview endpoint, allowing any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces. This occurs because the system fails to verify ownership or workspace permissions when a file's UUID is provided. Attackers can exploit this by accessing the '/console/api/files/{file id}/preview' endpoint using an intercepted
file id. Additionally, Dify Cloud permits unauthenticated free self-registration, which simplifies account creation for potential attackers.Recommendations
Update to version 1.14.2 or later.
As a temporary workaround, restrict access to the '/console/api/files/{file id}/preview' endpoint to minimize the risk of unauthorized document access.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dify