Ragflow
Vendor:
First CVE: Oct 19, 2024 · Active for 1 year
17
Total CVEs
More Total CVEs than 94% of tracked products
5.7
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 72% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ragflow over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 19, 2024
21 months ago
Most Recent CVE
Jul 2, 2026
25 days ago
CVE Severity & Scoring
Ragflow17 CVEs
29%
35%
35%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None14 (82.4%)
Unknown0 (0.0%)
Required3 (17.6%)
Privileges Required
Low8 (47.1%)
High0 (0.0%)
None9 (52.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24770CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allow | Jan 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-28797HIGH RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent | Apr 3, 2026 | 8.8 | 31 | NO | NO |
CVE-2025-27135CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement fr | Feb 25, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-68700HIGH RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary | Dec 31, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-48187CRITICAL RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account regist | May 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-69286CRITICAL RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assista | Dec 31, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-12433CRITICAL A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' w | Mar 20, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-10131HIGH The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_fa | Oct 19, 2024 | 8.8 | 26 | NO | NO |
CVE-2026-58579MEDIUM RAGFlow before 0.26.3 stores an agent pipeline (DSL) node name without sanitization: the agent update endpoint normalizes the submitted DSL via normalize_dsl, which only performs J | Jul 2, 2026 | 5.4 | 25 | NO | NO |
CVE-2024-12450CRITICAL In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attack | Mar 20, 2025 | 9.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Ragflow
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.17.2 | 1 | 6.1 | 0.3% | 0 | 0 |
| 0.13.0 | 2 | 7.0 | 0.6% | 0 | 0 |
| 0.12.0 | 4 | 6.8 | 0.7% | 0 | 0 |
| 0.11.0 | 1 | 8.8 | 1.1% | 0 | 0 |