infiniflow
AI / MLcommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting infiniflow.
- CVE-2026-75898RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component8.5
- CVE-2026-58579RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name5.4
- CVE-2026-45312RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution9.9
- CVE-2026-28797RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component8.8
- CVE-2026-24770RAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParser9.8
- CVE-2025-69286RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability9.8
- CVE-2025-68700RAGFlow Remote Code Execution Vulnerability8.8
- CVE-2025-51462Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeti...6.1
- CVE-2025-48187RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, an...9.1
- CVE-2024-12779SSRF in infiniflow/ragflow7.5
- CVE-2024-12869Improper Authentication in infiniflow/ragflow4.3
- CVE-2024-12871Stored Cross-site Scripting (XSS) in infiniflow/ragflow5.4
- CVE-2024-12450RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow9.8
- CVE-2024-12870Stored Cross-site Scripting (XSS) in infiniflow/ragflow5.4
- CVE-2024-12433Remote Code Execution in infiniflow/ragflow9.8