PT-2025-30456 · Ragflow · Ragflow
Geckosecurity
·
Published
2025-07-22
·
Updated
2025-07-23
·
CVE-2025-51462
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RAGFlow version 0.17.2
Description
A stored Cross-site Scripting (XSS) issue exists in the
api.apps.dialog app.set dialog function. This allows remote attackers to execute arbitrary JavaScript code through crafted input to the assistant greeting field. The input is stored without sanitization and rendered using a markdown component with rehype-raw.Recommendations
Update to a newer version that contains a fix for this issue. As a temporary workaround, consider sanitizing the
assistant greeting input before storing it.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ragflow