OVERVIEW CVE-2026-6587 is a server-side request forgery (SSRF) vulnerability affecting vibrantlabsai RAGAS versions up to 0.4.3. The flaw exists in the Collections Module, specifically within the _try_process_local_file and _try_process_url functions in src/ragas/metrics/collections/multi_modal_faithfulness/util.py. An attacker can manipulate the retrieved_contexts argument to trigger malicious requests from the affected server. SEVERITY This vulnerability carries a CVSS 3.1 score of 6.3 (MEDIUM), with a network-based attack vector requiring only low complexity and valid authentication credentials. The attack requires no user interaction. The impact is limited to confidentiality, integrity, and availability of the affected system. While the EPSS score of 0.000110 indicates relatively low prevalence among all CVEs, the FAUCET Risk Score of 44.0 reflects moderate overall risk. EXPLOITATION STATUS The vulnerability has an active listing on the Hot List and is actively being monitored. Public exploit code has been released and is available for potential attackers. The vendor was contacted early during disclosure but failed to respond or engage with the security research community. A previous patch for CVE-2025-45691 was applied only to a different module, leaving this vulnerability unaddressed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vibrantlabsai | RAGAS | 0.4.0, 0.4.1, 0.4.2, 0.4.3CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.