CVE-2026-28797
RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component
Description
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary operating system commands on the server. At time of publication, there are no publicly available patches.
In plain language
AI Act nowCVE-2026-28797 is a RAGFlow bug where an authenticated user can inject instructions into a template feature and cause the server to run commands; small businesses running RAGFlow (especially older versions up to 0.24.0) should treat this as actively dangerous.
In RAGFlow, an authenticated Server-Side Template Injection (SSTI) in the Agent “Text Processing” (StringTransform) and Message components lets a user supply a template that is rendered by unsandboxed jinja2.Template, enabling Remote Code Execution (RCE) on the server.
What to do now
- Check whether your deployment uses RAGFlow and whether its version is 0.24.0 or earlier.
- Verify which accounts (and authentication method) can access the Agent workflow “Text Processing” / template-like features.
- If you are affected and no patch is available for your version, immediately restrict access so only the minimum trusted accounts can reach RAGFlow (and especially the Agent workflow endpoints involved).
- If possible in your setup, disable or remove the Agent “Text Processing” workflow (StringTransform) and any Message/template rendering functionality until a fixed version is available.
- Re-check after any vendor update or rebuild whether a fixed release exists for your exact RAGFlow version branch, and upgrade as soon as a patch becomes available.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-28797 and every CVE in our database. Create a free account — no credit card required.
Create Free Account