[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":54,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":61,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":67,"vulnerability-29714":74},[4,15,21,27,33,39,44],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",{"title":45,"slug":46,"text":47,"link":48,"external":49,"targets":50,"cta":53,"variant":13,"campaign_id":46},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 16] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[51,52],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",55],{"key":56,"params":57,"result":59},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":58},"{}",{"head":60},{},["Island",62],{"key":63,"params":64,"result":65},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":58},{"head":66},{},["Island",68],{"key":69,"params":70,"result":72},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":71},"{\"text-color\":\"gray\"}",{"head":73},{},{"id":75,"detectable_with":76,"vuln_details":83,"vuln_id":104,"name":105,"published":106,"updated":84},29714,{"tool":77,"engine":80},{"id":78,"name":79},1,"Network Scanner",{"id":81,"name":82},2,"Nuclei",{"id":75,"codename":84,"description":84,"severity":85,"risk_description":86,"public_description":87,"public_recommendation":88,"recommendation":84,"references":89,"cvssv3":96,"epss_score":97,"epss_percentile":98,"cve":99,"in_cisa_catalog":9,"date":101,"software_type":84,"vendor":102,"product":103,"ptt_exploit_capabilities":84},null,"critical","Unauthenticated attackers can traverse the Plugin Daemon's internal REST API, leaking system metadata (version hash, platform, pool capacity). Any internal Plugin Daemon endpoint is reachable, meaning any new endpoint becomes instantly exploitable from the public internet without credentials.","Dify version 1.14.1 and prior are affected by an unauthenticated path traversal in the Plugin Daemon icon proxy endpoint. The \u002Fconsole\u002Fapi\u002Fworkspaces\u002Fcurrent\u002Fplugin\u002Ficon endpoint requires no authentication and passes the filename query parameter unsanitized into the internal Plugin Daemon REST API URL. Using ..\u002F dot-sequence traversal an attacker escapes the authorized plugin\u002F{tenant_id}\u002Fasset\u002F namespace and reaches arbitrary internal Plugin Daemon endpoints. The \u002Fhealth\u002Fcheck endpoint is always available and returns Plugin Daemon version, build time and pool status confirming exploitation.","Upgrade to Dify 1.15.0 or later. The fix in api\u002Fcore\u002Fplugin\u002Fimpl\u002Fbase.py (BasePluginClient._prepare_request) URL-decodes the path and raises ValueError on any segment containing .. or %2e%2e, preventing path traversal sequences from being forwarded to the Plugin Daemon.",[90,91,92,93,94,95],"https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-41948","https:\u002F\u002Fwww.zafran.io\u002Fresources\u002Fdifytap-zafran-discovers-how-attackers-can-silently-wiretap-ai-data-across-tenants-on-a-platform-powering-1m-apps","https:\u002F\u002Fhuntr.com\u002Fbounties\u002F35b7ad59-e35d-443f-bf77-387bfb932ec0","https:\u002F\u002Fgithub.com\u002Flanggenius\u002Fdify\u002Fpull\u002F35796","https:\u002F\u002Fosv.dev\u002Fvulnerability\u002FCVE-2026-41948","https:\u002F\u002Fwww.vulncheck.com\u002Fadvisories\u002Fdify-path-traversal-via-plugin-daemon-internal-api-access",9.4,0.0739,0.94074,[100],"CVE-2026-41948","2026-05-18T00:00:00Z","langgenius","dify","NETSCAN-NUCLEI-CVE-CVE-2026-41948","Dify \u003C=1.14.1 - Unauthenticated Plugin Daemon Path Traversal","2026-09-15T00:00:00Z"]