VYPR
Vendor

RAGFlow

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-51897CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.00

    RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution

  • CVE-2024-53450HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.01

    RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.

  • CVE-2025-51462MedJul 22, 2025
    risk 0.00cvss 6.1epss 0.00

    Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with…