Dify <=1.14.1 - Unauthenticated Plugin Daemon Path Traversal CVE-2026-41948

Detectable with
Network Scanner
Scan engine
Nuclei
Cisa Kev
No
Exploitable with Sniper
No
CVE Published
May 18, 2026
Detection added at
Software Type
Not available
Vendor
langgenius
Product
dify

Detect this vulnerability now!

Check your clients' targets (or your own) for this vulnerability and thousands more! Get proof for validation with our ethical hacking toolkit.