漏洞描述
Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in the Plugin Daemon icon proxy endpoint. The /console/api/workspaces/current/plugin/icon endpoint requires no authentication and passes the filename query parameter unsanitized into the internal Plugin Daemon REST API URL. Using ../ dot-sequence traversal an attacker escapes the authorized plugin/{tenant_id}/asset/ namespace and reaches arbitrary internal Plugin Daemon endpoints. The /health/check endpoint is always available and returns Plugin Daemon version, build time and pool status confirming exploitation.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41948↗www.zafran.iohttps://www.zafran.io/resources/difytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps↗huntr.comhttps://huntr.com/bounties/35b7ad59-e35d-443f-bf77-387bfb932ec0↗github.comhttps://github.com/langgenius/dify/pull/35796↗osv.devhttps://osv.dev/vulnerability/CVE-2026-41948↗www.vulncheck.comhttps://www.vulncheck.com/advisories/dify-path-traversal-via-plugin-daemon-internal-api-access↗