PT-2026-33656 · Vibrantlabsai · Ragas

·

CVE-2026-6587

·

Published

2026-04-20

·

Updated

2026-07-13

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions vibrantlabsai RAGAS versions prior to 0.4.4
Description A server-side request forgery exists in the Collections Module. A remote attacker can initiate this by manipulating the retrieved contexts argument within the try process local file() and try process url() functions located in the src/ragas/metrics/collections/multi modal faithfulness/util.py file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting the use of the try process local file() and try process url() functions.

Exploit

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6587
GHSA-95WW-475F-PR4F
PYSEC-2026-3046

Affected Products

Ragas