Critical severity9.8NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-12433
CVE-2024-12433
Description
A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication without restrictions. Additionally, the server processes incoming data using pickle deserialization via pickle.loads() on connection.recv(), making it vulnerable to remote code execution. This issue is fixed in version 0.14.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*range: >=0.12.0,<0.14.0
- (no CPE)range: <0.14.0
- infiniflow/infiniflow/ragflowv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/infiniflow/ragflow/commit/49494d4e3c8f06a5e52cf1f7cce9fa03cadcfbf6nvdPatch
- huntr.com/bounties/8a1465af-09e4-42af-9e54-0b70e7c87499nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.