VYPR
Critical severity9.8NVD Advisory· Published Feb 25, 2025· Updated Jun 17, 2026

CVE-2025-27135

CVE-2025-27135

Description

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched version is available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*range: <=0.15.1
    • (no CPE)range: <=0.15.1
    • (no CPE)range: <= 0.15.1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.