VYPR

Ragflow

by Infiniflow

Source repositories

CVEs (21)

  • CVE-2024-12433CriMar 20, 2025
    risk 0.00cvss 9.8epss 0.02

    A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication without restrictions.…

Page 2 of 2