Infiniflow
Infiniflow Ragflow: vulnerabilidades y CVE
Infiniflow Ragflow tiene 27 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE27
Últimos 12 meses14
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-51897 | Sin puntuar | — | — | 1 oct 2026 | RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution |
| CVE-2026-51896 | Sin puntuar | — | — | 1 oct 2026 | infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations. |
| CVE-2026-51895 | Sin puntuar | — | — | 1 oct 2026 | Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing… |
| CVE-2026-51894 | Sin puntuar | — | — | 1 oct 2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner,… |
| CVE-2026-51893 | Sin puntuar | — | — | 1 oct 2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a… |
| CVE-2026-51892 | Sin puntuar | — | — | 1 oct 2026 | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. |
| CVE-2026-93013 | Media (5.3) | 0.51% | — | 17 sept 2026 | RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying… |
| CVE-2026-75898 | Alta (8.4) | 0.39% | — | 18 ago 2026 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and… |
| CVE-2026-58579 | Media (5.1) | 0.30% | — | 2 jul 2026 | RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs JSON serialization validation and… |
| CVE-2026-45312 | Crítica (9.9) | 0.52% | — | 29 may 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute… |
| CVE-2026-28797 | Alta (8.7) | 0.56% | — | 3 abr 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing… |
| CVE-2026-24770 | Crítica (9.8) | 1.4% | — | 27 ene 2026 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary… |
| CVE-2025-69286 | Alta (8.9) | 0.79% | — | 31 dic 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation… |
| CVE-2025-68700 | Alta (8.6) | 0.72% | — | 31 dic 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host… |
| CVE-2025-51462 | Media (6.1) | 0.29% | — | 22 jul 2025 | Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is… |
| CVE-2025-48187 | Crítica (9.8) | 0.54% | — | 17 may 2025 | RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset.… |
| CVE-2024-12880 | Media (6.5) | 0.68% | — | 20 mar 2025 | A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access… |
| CVE-2024-12871 | Media (5.4) | 0.39% | — | 20 mar 2025 | An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the… |
| CVE-2024-12870 | Media (5.4) | 0.51% | — | 20 mar 2025 | A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload HTML/XML files that can host… |
| CVE-2024-12869 | Media (4.3) | 0.54% | — | 20 mar 2025 | In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private… |
| CVE-2024-12779 | Alta (7.5) | 0.65% | — | 20 mar 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversation/tts` endpoints. Attackers can specify… |
| CVE-2024-12450 | Crítica (9.8) | 1.3% | — | 20 mar 2025 | In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by… |
| CVE-2024-12433 | Crítica (9.8) | 1.7% | — | 20 mar 2025 | A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers… |
| CVE-2025-27135 | Alta (8.9) | 0.62% | — | 25 feb 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to… |
| CVE-2025-25282 | Alta (8.1) | 0.49% | — | 21 feb 2025 | RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to… |
| CVE-2024-53450 | Alta (7.5) | 0.54% | — | 9 dic 2024 | RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents. |
| CVE-2024-10131 | Alta (8.8) | 1.1% | — | 19 oct 2024 | The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.