PT-2025-54459 · Ragflow · Ragflow

Published

2025-12-31

·

Updated

2026-01-06

·

CVE-2025-68700

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions RAGFlow versions prior to 0.23.0
Description RAGFlow is a Retrieval-Augmented Generation engine susceptible to arbitrary system command execution. A low-privileged authenticated user can execute commands on the server host process through the Canvas CodeExec component, bypassing sandbox isolation. This is due to the use of eval() on untrusted data (standard output) without filtering or sandboxing, intended to convert string results into Python objects. Additional API endpoints lack access control or have incorrect permission logic, increasing the attack surface. The eval() function allows execution of attacker-controlled code.
Recommendations Update to version 0.23.0 or later.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-68700
GHSA-8XW3-V6C2-J84J

Affected Products

Ragflow