Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Wangyihang

#14818of 53,633
18.2Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-30249
8.8
2026-04-03
Infiniflow · Ragflow · CVE-2026-28797
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary operating system commands on the server. At time of publication, there are no publicly available patches.
PT-2025-4386
9.4
2025-01-10
Atheros · Atheos · CVE-2025-22152
**Name of the Vulnerable Software and Affected Versions** Atheos versions prior to v600 **Description** Atheos is a self-hosted browser-based cloud IDE. The issue is related to the lack of proper validation of the `$path` and `$target` parameters across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. This can be exploited through various attack vectors present in multiple PHP files. **Recommendations** For versions prior to v600, update to v600 to fix the issue. As a temporary workaround, consider restricting access to the vulnerable parameters `$path` and `$target` to minimize the risk of exploitation.