Arbitrary Code Execution Vulnerability in RAGFlow Open-Source Engine
CVE-2025-68700
What is CVE-2025-68700?
The RAGFlow open-source engine contains a vulnerability in versions prior to 0.23.0, allowing low-privileged authenticated users to execute arbitrary system commands on the server. This exploitation occurs through the Canvas CodeExec component which uses eval() without proper filtering or sandboxing, making it susceptible to executing untrusted data. Additionally, some endpoints may lack adequate access controls or exhibit inverted permission logic, leading to an increased attack surface. A patch addressing this vulnerability has been implemented in version 0.23.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ragflow < 0.23.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
