Arbitrary Code Execution Vulnerability in RAGFlow Open-Source Engine
CVE-2025-68700

8.6HIGH

Key Information:

Vendor

Infiniflow

Status
Vendor
CVE Published:
31 December 2025

What is CVE-2025-68700?

The RAGFlow open-source engine contains a vulnerability in versions prior to 0.23.0, allowing low-privileged authenticated users to execute arbitrary system commands on the server. This exploitation occurs through the Canvas CodeExec component which uses eval() without proper filtering or sandboxing, making it susceptible to executing untrusted data. Additionally, some endpoints may lack adequate access controls or exhibit inverted permission logic, leading to an increased attack surface. A patch addressing this vulnerability has been implemented in version 0.23.0.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

ragflow < 0.23.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.