Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-45312: RAGFlow 0.24.0 and earlier: Unauthorized OS Command Execution
CVE-2026-45312
Summary
RAGFlow's open-source engine has a security flaw that allows authenticated users to run system commands on the server. This is a concern because any registered user can exploit this vulnerability. To protect your system, update RAGFlow to the latest version.
Original title
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated...
Original description
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI.
nvd CVSS3.1
9.9
Vulnerability type
CWE-1336
Published: 29 May 2026 · Updated: 31 May 2026 · First seen: 29 May 2026