CVE Tools

CVE-2026-28797

RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component

Published: Apr 3, 2026Updated: Jul 24, 2026 Sources: CVE List NVDCWE-20

Description

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary operating system commands on the server. At time of publication, there are no publicly available patches.

In plain language

AI Act now

CVE-2026-28797 is a RAGFlow bug where an authenticated user can inject instructions into a template feature and cause the server to run commands; small businesses running RAGFlow (especially older versions up to 0.24.0) should treat this as actively dangerous.

Executive summary

In RAGFlow, an authenticated Server-Side Template Injection (SSTI) in the Agent “Text Processing” (StringTransform) and Message components lets a user supply a template that is rendered by unsandboxed jinja2.Template, enabling Remote Code Execution (RCE) on the server.

If affected, business impact
Server takeover via command executionData theft from the RAGFlow hostRansomware risk from full compromiseService disruption and downtime

What to do now

  1. Check whether your deployment uses RAGFlow and whether its version is 0.24.0 or earlier.
  2. Verify which accounts (and authentication method) can access the Agent workflow “Text Processing” / template-like features.
  3. If you are affected and no patch is available for your version, immediately restrict access so only the minimum trusted accounts can reach RAGFlow (and especially the Agent workflow endpoints involved).
  4. If possible in your setup, disable or remove the Agent “Text Processing” workflow (StringTransform) and any Message/template rendering functionality until a fixed version is available.
  5. Re-check after any vendor update or rebuild whether a fixed release exists for your exact RAGFlow version branch, and upgrade as soon as a patch becomes available.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

infiniflow
commercialaka infiniflow/ragflow, ragflow

Exploitability

Workaround Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-28797 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows