CVE-2026-75898
- EPSS 0.3%
- Veröffentlicht 18.08.2026 14:24:06
- Zuletzt bearbeitet 18.08.2026 15:17:15
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and...
CVE-2026-58579
- EPSS 0.18%
- Veröffentlicht 02.07.2026 19:38:51
- Zuletzt bearbeitet 14.07.2026 23:17:32
RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The...
CVE-2026-45312
- EPSS 0.29%
- Veröffentlicht 29.05.2026 12:24:07
- Zuletzt bearbeitet 21.07.2026 12:10:00
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server....
CVE-2026-28797
- EPSS 0.39%
- Veröffentlicht 03.04.2026 21:41:54
- Zuletzt bearbeitet 24.07.2026 22:10:00
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. Th...
CVE-2026-24770
- EPSS 0.91%
- Veröffentlicht 27.01.2026 21:51:44
- Zuletzt bearbeitet 30.01.2026 21:53:46
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to...
CVE-2025-69286
- EPSS 0.51%
- Veröffentlicht 31.12.2025 21:52:54
- Zuletzt bearbeitet 06.01.2026 16:47:58
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to b...
CVE-2025-68700
- EPSS 0.5%
- Veröffentlicht 31.12.2025 21:17:40
- Zuletzt bearbeitet 06.01.2026 18:02:07
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas Co...
CVE-2025-51462
- EPSS 0.29%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 09.10.2025 16:02:10
Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered us...
CVE-2025-48187
- EPSS 0.54%
- Veröffentlicht 17.05.2025 00:00:00
- Zuletzt bearbeitet 12.06.2025 16:29:12
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is n...
CVE-2024-12779
- EPSS 0.64%
- Veröffentlicht 20.03.2025 10:11:28
- Zuletzt bearbeitet 01.04.2025 20:34:50
A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversation/tts` endpoints. Attackers can specify an arbitrary URL as the `api_b...