Junglewise Threat Intelligence

CVE-2026-41950: LangGenius Dify authorization bypass in chat-messages endpoint

CVE-2026-41950 · Severity: medium · CVSS 6.5 · Published 2026-05-05

Technologies: Langgenius Dify. Vendors: Langgenius.

Executive brief

Dify is an open-source platform used to build and manage AI applications and workflows. A security flaw allowed logged-in users to view files uploaded by other people within the same organization or tenant. By exploiting this, an attacker could bypass privacy protections to access sensitive documents, images, or data used in AI chats.

Technical details

An authorization bypass exists in Dify's chat-messages endpoints due to insufficient permission verification. Authenticated users can supply an arbitrary file UUID in the 'files' array of a chat-messages request to access files they do not own. This flaw allows attackers to bypass workspace separation and signed URL protections, retrieving sensitive file contents through workflow processing. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and was addressed in version 1.14.0.

Affected products

  • LangGenius Dify before 1.14.0

Timeline

  • 2026-04-29: patched: Version 1.14.0 released on GitHub
  • 2026-05-05: disclosed: Initial vulnerability disclosure and NVD publication
  • 2026-06-22: advisory: Detailed security blog post by Zafran Security published

References

Related threats