๐Ÿ” CVE Alert

CVE-2026-45312

CRITICAL 9.9

RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution

CVSS Score
9.9
EPSS Score
0.0%
EPSS Percentile
15th

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI.

CWE CWE-1336
Vendor infiniflow
Product ragflow
Published May 29, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for infiniflow ragflow

Be the first to know when new critical vulnerabilities affecting infiniflow ragflow are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

infiniflow / ragflow
<= 0.24.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/infiniflow/ragflow/security/advisories/GHSA-wpg4-h5g2-jxm6