PT-2026-5027 · Ragflow · Ragflow

Espanda666

·

Publicado

2026-01-27

·

Atualizado

2026-02-09

·

CVE-2026-24770

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RAGFlow versions prior to 0.23.1
Description RAGFlow, an open-source RAG (Retrieval-Augmented Generation) engine, is affected by a "Zip Slip" issue in the MinerU parser. This allows an attacker to overwrite arbitrary files on the server, potentially leading to Remote Code Execution (RCE) through a malicious ZIP archive. The vulnerability resides in the extract zip no root function, which fails to sanitize filenames within the ZIP archive. Approximately 3,000 instances are reportedly exposed. The vulnerability is present in version 0.23.1 and potentially earlier versions. The MinerUParser class retrieves and extracts ZIP files from an external source using the mineru server url.
Recommendations Versions prior to 0.23.1 should be updated to version 0.23.1 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24770
GHSA-V7CF-W7GJ-PGF4

Produtos afetados

Ragflow