Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution | |
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | |
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. | |
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or membership binding on that object. | |
| Recibida | Sin puntuar | — | — | Infiniflow RagflowAI | 1/10/2026 | 1/10/2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. | |
| Aplazada | Media (5.3) | 0.51% | — | Infiniflow RagflowAI | 17/9/2026 | 21/9/2026 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing… | |
| Aplazada | Alta (8.4) | 0.39% | — | Infiniflow RagflowAI | 18/8/2026 | 16/9/2026 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without… | |
| Aplazada | Media (5.1) | 0.30% | — | Infiniflow RagflowAI | 2/7/2026 | 14/7/2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and preserves the node name verbatim. The dataflow-result web UI then renders that name into the "Rerun from… | |
| Aplazada | Crítica (9.9) | 0.52% | — | Infiniflow RagflowAI | 29/5/2026 | 21/7/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a… | |
| Analizada | Alta (8.7) | 0.56% | — | Infiniflow Ragflow | 3/4/2026 | 24/7/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render… | |
| Analizada | Crítica (9.8) | 1.4% | — | Infiniflow Ragflow | 27/1/2026 | 17/6/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to Remote Code Execution) via a malicious ZIP archive. The MinerUParser… | |
| Analizada | Alta (8.9) | 0.79% | — | Infiniflow Ragflow | 31/12/2025 | 23/9/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using… | |
| Analizada | Alta (8.6) | 0.72% | — | Infiniflow Ragflow | 31/12/2025 | 23/9/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas CodeExec component, completely bypassing sandbox isolation. This occurs… | |
| Analizada | Media (6.1) | 0.29% | — | Infiniflow Ragflow | 22/7/2025 | 17/6/2026 | Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with rehype-raw. | |
| Analizada | Crítica (9.8) | 0.54% | — | Infiniflow Ragflow | 17/5/2025 | 17/6/2026 | RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting. | |
| Modificada | Media (6.5) | 0.68% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants, they can manipulate their tenant access to query and access API tokens of other… | |
| Analizada | Media (5.4) | 0.39% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to session hijacking, data exfiltration, or unauthorized actions… | |
| Aplazada | Media (5.4) | 0.51% | — | Infiniflow RagflowAI | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload HTML/XML files that can host arbitrary JavaScript payloads. These files are served with the 'application/xml' content type, which is… | |
| Modificada | Media (4.3) | 0.54% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their… | |
| Analizada | Alta (7.5) | 0.65% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversation/tts` endpoints. Attackers can specify an arbitrary URL as the `api_base` when adding an `OPENAITTS` model, and subsequently access the… | |
| Modificada | Crítica (9.8) | 1.3% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files.… | |
| Analizada | Crítica (9.8) | 1.7% | — | Infiniflow Ragflow | 20/3/2025 | 17/6/2026 | A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication without restrictions. Additionally, the server processes incoming… | |
| Analizada | Alta (8.9) | 0.62% | — | Infiniflow Ragflow | 25/2/2025 | 17/6/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched version is available. | |
| Analizada | Alta (8.1) | 0.49% | — | Infiniflow Ragflow | 21/2/2025 | 17/6/2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts, add user account into other tenant).… |