Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-6587

25
FAUCET Score

OVERVIEW CVE-2026-6587 is a server-side request forgery (SSRF) vulnerability affecting vibrantlabsai RAGAS versions up to 0.4.3. The flaw exists in the Collections Module, specifically within the _try_process_local_file and _try_process_url functions in src/ragas/metrics/collections/multi_modal_faithfulness/util.py. An attacker can manipulate the retrieved_contexts argument to trigger malicious requests from the affected server. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.3 (MEDIUM), with a network-based attack vector requiring only low complexity and valid authentication credentials. The attack requires no user interaction. The impact is limited to confidentiality, integrity, and availability of the affected system. While the EPSS score of 0.000110 indicates relatively low prevalence among all CVEs, the FAUCET Risk Score of 44.0 reflects moderate overall risk. EXPLOITATION STATUS The vulnerability has an active listing on the Hot List and is actively being monitored. Public exploit code has been released and is available for potential attackers. The vendor was contacted early during disclosure but failed to respond or engage with the security research community. A previous patch for CVE-2025-45691 was applied only to a different module, leaving this vulnerability unaddressed.

Impacted Technologies

VendorProductVersion(s)CPE
VibrantlabsaiRAGAS
0.4.0, 0.4.1, 0.4.2, 0.4.3CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.28%
Probability of exploitation in next 30 days
EPSS Percentile
19.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0028 is in the 25th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatno patchvia redhat_api
Product: Red Hat OpenShift AI (RHOAI)Fixed in: rhoai/odh-llama-stack-core-rhel9

Vendor Advisories (2)

pipGHSA-95ww-475f-pr4flow

RAGAS has SSRF via Multi-Modal Faithfulness Collections Module

Apr 20, 2026
redhatCVE-2026-6587Important

vibrantlabsai RAGAS: vibrantlabsai RAGAS: Server-Side Request Forgery via retrieved_contexts argument manipulation

Apr 20, 2026

References

access.redhat.com / security/cve/CVE-2026-6587
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-6587.json
adithyanak.com / ragas-v0214-arbitrary-file-read-vulnerability
vuldb.com / submit/791088
vuldb.com / vuln/358222
vuldb.com / vuln/358222/cti