CVE-2026-28797 identifies a critical Server-Side Template Injection (SSTI) vulnerability affecting RAGFlow versions 0.24.0 and prior. This flaw resides in the Agent workflow's Text Processing and Message components, which utilize unsandboxed Jinja2 templates, enabling authenticated users to execute arbitrary operating system commands. Rated with a CVSSv4 score of 8.7 (High), the vulnerability has low attack complexity and network access, posing a high risk to confidentiality, integrity, and availability. Currently, no patches are available, and there is no public exploit code or evidence of active exploitation, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.24.0CPE matchmatch criteria | cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.