Path Traversal Vulnerability in RAGapp Knowledge File Handler
CVE-2026-13509
Key Information:
Badges
What is CVE-2026-13509?
A path traversal vulnerability exists in the RAGapp Knowledge File Handler, affecting versions up to 0.1.5. The flaw resides in the 'FileHandler.upload_file' and 'FileHandler.remove_file' functions within the 'src/ragapp/backend/controllers/files.py' file. This vulnerability allows attackers to manipulate file paths, potentially gaining unauthorized access to sensitive information. As the exploit is publicly known, it poses a risk of remote execution, making prompt remediation crucial. A fix is currently pending review.
Affected Version(s)
RAGapp 0.1.0
RAGapp 0.1.1
RAGapp 0.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
