CVE-2026-51896
- EPSS 0.15%
- Veröffentlicht 01.10.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 19:17:22
infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
CVE-2026-51894
- EPSS 0.14%
- Veröffentlicht 01.10.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 16:17:13
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership ...
CVE-2026-51893
- EPSS 0.14%
- Veröffentlicht 01.10.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 19:17:22
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, ...
CVE-2026-51892
- EPSS 0.15%
- Veröffentlicht 01.10.2026 00:00:00
- Zuletzt bearbeitet 05.10.2026 19:17:22
infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.
CVE-2026-93013
- EPSS 0.35%
- Veröffentlicht 17.09.2026 15:16:51
- Zuletzt bearbeitet 21.09.2026 21:17:17
RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_pat...
CVE-2026-75898
- EPSS 0.3%
- Veröffentlicht 18.08.2026 14:24:06
- Zuletzt bearbeitet 16.09.2026 13:42:44
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and...
CVE-2026-58579
- EPSS 0.18%
- Veröffentlicht 02.07.2026 19:38:51
- Zuletzt bearbeitet 14.07.2026 23:17:32
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The...
CVE-2026-45312
- EPSS 0.29%
- Veröffentlicht 29.05.2026 12:24:07
- Zuletzt bearbeitet 21.07.2026 12:10:00
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server....
CVE-2026-28797
- EPSS 0.39%
- Veröffentlicht 03.04.2026 21:41:54
- Zuletzt bearbeitet 24.07.2026 22:10:00
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. Th...
CVE-2026-24770
- EPSS 0.91%
- Veröffentlicht 27.01.2026 21:51:44
- Zuletzt bearbeitet 30.01.2026 21:53:46
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to...