Dify 1.14.2 patches security gaps and workflow bugs

Dify v1.14.2 is a patch release that tightens tenant isolation, restricts tool credential changes, and fixes several workflow, tracing, and knowledge-base issues. The update also changes Docker environment file layout and requires a database migration for configurable Explore app categories.

Dify 1.14.2 patches security gaps and workflow bugs

Dify has released v1.14.2, a patch update that focuses on security hardening, workflow reliability, knowledge-base fixes, observability, and deployment changes after v1.14.1, according to the release notes.

On the security side, the company said it strengthened tenant isolation for app trace-config endpoints and the FilePreview text extraction path. Those changes were credited to @xr843 in pull requests #35793 and #35797, and were called out under security fixes in the release announcement.

⚡ New to this?

This is a software update for Dify, a platform used to build AI apps and workflows. The main news is that it patches security issues around tenant isolation and admin access, and it fixes several bugs that could affect workflows, knowledge retrieval, and tracing.

A tenant is a separate customer or workspace inside a shared system, so tenant isolation means one group should not be able to touch another group’s data. RAG, or retrieval-augmented generation, means an AI model pulls in files or knowledge from a database before answering, so fixes there can affect how accurate and reliable responses are.

🦞 OpenClaw angle

If you run self-hosted AI automation with Dify, treat this as a maintenance release, not just a feature update. Run the required database migration before bringing the service back up, and review any custom docker-compose or .env changes because the Docker env files have been split into categorized directories.

If you manage workspaces with multiple admins or tenants, audit any automation that touches trace-config, file preview, or builtin tool credentials. Also check workflows that depend on HITL resume, RAG pipelines, or document summaries, since those paths received fixes and may behave differently after the update.

The release also tightens tool credential handling. According to the changelog, updates to default builtin tool credentials are now restricted to workspace admins and owners, and stale tenant tool credentials are cleaned up during the reset-encrypt-key-pair command. Dify credited @NeatGuyCoding and @xr843 for those changes in #36264 and #35843.

A large portion of the patch is aimed at workflow stability. The release notes say tracing was restored after HITL, or human-in-the-loop, workflow resume, workflow run callback tracking was improved, message-update database roundtrips were reduced, memory fetches outside Flask context were fixed, and base64 file lookup sessions are now closed correctly. Those fixes were contributed across #36064, #36149, #36213, #36253, and #36308.

Dify also said it fixed several workflow and model-selection issues, including loading behavior when no model is selected, filtering model presets by supported parameters, and improving API extension dialog controls. On the knowledge side, the release includes fixes for knowledge hit-testing rendering, empty knowledge creation, recommended app category ordering, and null handling in recommended app detail retrieval.

For RAG, short for retrieval-augmented generation, the release notes say LLM nodes can now access retrieved knowledge files. Dify also regenerated document summaries after API updates, fixed pipeline template rendering, and handled credential fetch failures in RAG pipelines more gracefully.

The web UI got a set of smaller fixes and product updates. Dify said app creation now tracks the creation source and template ID, the browser is used to initialize user timezone and language, and web app icons and descriptions now display correctly. The annotation and dataset UI was also adjusted, including support for annotation reply score thresholds below 0.8 and a redirect for unauthorized knowledge editors back to datasets.

On observability, Dify said it isolated Langfuse v3 SDK TracerProvider instances to prevent cross-task interference and added Phoenix parent trace fallback behavior. For deployment, the release bumps plugin-daemon to 0.6.1, increases the default GraphEngine minimum worker count, and refreshes Docker README references.

The upgrade guide says this release includes a new database migration for configurable Explore app categories, so database migrations must be run during upgrade. It also says Docker Compose environment variables are now split into categorized files under docker/envs/**, which means anyone maintaining a customized docker-compose.yaml or .env file should review the new layout and re-apply local customizations carefully.

For self-hosted deployments, Dify said explicitly configured SECRET_KEY values are still respected. If SECRET_KEY is empty, the system now generates and persists a runtime key automatically. The release is available as v1.14.2, with the full changelog listing the security fixes, workflow changes, UI updates, and deployment notes.

Source: Dify Releases ↗

More from Security News