PT-2025-21792 · Ragflow · Ragflow
Published
2025-05-17
·
Updated
2025-05-22
·
CVE-2025-48187
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
RAGFlow versions 0.18.1 and earlier
Description:
The issue allows account takeover due to the possibility of conducting successful brute-force attacks against email verification codes. This enables arbitrary account registration, login, and password reset. The codes are six digits and there is no rate limiting, making it easier for attackers to guess the codes.
Recommendations:
For RAGFlow versions 0.18.1 and earlier, consider implementing rate limiting on email verification codes to prevent brute-force attacks until a patch is available. As a temporary workaround, restrict access to the email verification code feature to minimize the risk of exploitation.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ragflow