Arbitrary Code Execution Vulnerability in RAGFlow Open-Source Engine
CVE-2025-68700
8.6HIGH
What is CVE-2025-68700?
The RAGFlow open-source engine contains a vulnerability in versions prior to 0.23.0, allowing low-privileged authenticated users to execute arbitrary system commands on the server. This exploitation occurs through the Canvas CodeExec component which uses eval() without proper filtering or sandboxing, making it susceptible to executing untrusted data. Additionally, some endpoints may lack adequate access controls or exhibit inverted permission logic, leading to an increased attack surface. A patch addressing this vulnerability has been implemented in version 0.23.0.
Affected Version(s)
ragflow < 0.23.0
