PT-2025-54469 · Ragflow · Ragflow

Publicado

2025-12-31

·

Atualizado

2026-01-02

·

CVE-2025-69286

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RAGFlow versions prior to 0.22.0
Description RAGFlow is a Retrieval-Augmented Generation engine. Versions prior to 0.22.0 utilize an insecure key generation algorithm when creating API keys and beta tokens (assistant/agent share auth). This allows these tokens to be mutually derivable. An attacker obtaining the shared assistant/agent URL can derive the personal API key, gaining full control over the assistant/agent owner's account. The key generation process uses the URLSafeTimedSerializer with predictable inputs.
Recommendations Update to version 0.22.0 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69286
GHSA-9J5G-G4XM-57W7

Produtos afetados

Ragflow