A critical path traversal vulnerability (CVSS 9.4) in Dify that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization, accessing internal private endpoints.