PT-2026-5027 · Ragflow · Ragflow
Espanda666
·
Publicado
2026-01-27
·
Atualizado
2026-02-09
·
CVE-2026-24770
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RAGFlow versions prior to 0.23.1
Description
RAGFlow, an open-source RAG (Retrieval-Augmented Generation) engine, is affected by a "Zip Slip" issue in the MinerU parser. This allows an attacker to overwrite arbitrary files on the server, potentially leading to Remote Code Execution (RCE) through a malicious ZIP archive. The vulnerability resides in the
extract zip no root function, which fails to sanitize filenames within the ZIP archive. Approximately 3,000 instances are reportedly exposed. The vulnerability is present in version 0.23.1 and potentially earlier versions. The MinerUParser class retrieves and extracts ZIP files from an external source using the mineru server url.Recommendations
Versions prior to 0.23.1 should be updated to version 0.23.1 or later.
Exploit
Correção
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ragflow