Infiniflow maintains a narrowly focused portfolio centered on RAGFlow, a retrieval-augmented generation platform positioned in the document-processing and AI application stack. Its vulnerability profile skews toward critical-severity outcomes and concentrates on access-control and code-execution weakness classes, including authorization bypass through user-controlled keys, code injection, cross-site scripting, and OS command injection—a pattern reflecting the document-handling and server-side execution demands of a content-processing application. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Infiniflow over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24770CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allow | Jan 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-28797HIGH RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent | Apr 3, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-27135CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement fr | Feb 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-68700HIGH RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-48187CRITICAL RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account regist | May 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-69286CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assista | Dec 31, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-12433CRITICAL A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' w | Mar 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-10131HIGH The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_fa | Oct 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2026-58579MEDIUM RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs J | Jul 2, 2026 | 5.4 | 25 | NO | NO |
CVE-2024-12450CRITICAL In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attack | Mar 20, 2025 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Infiniflow.
Media articles that mention a CVE ID that affects a product developed by Infiniflow — matched by CVE ID, not by vendor name.