CVE-2026-93013
RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.
| CWE | CWE-22 |
| Vendor | infiniflow |
| Product | ragflow |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for infiniflow ragflow
Be the first to know when new medium vulnerabilities affecting infiniflow ragflow are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
infiniflow / ragflow
0 โค 0.27.2
References
github.com: https://github.com/infiniflow/ragflow/issues/19122 github.com: https://github.com/infiniflow/ragflow/pull/19591 github.com: https://github.com/infiniflow/ragflow/commit/aa78e8d224e0eab818d9fcd46f8791ebd73831bd github.com: https://github.com/infiniflow/ragflow/blob/v0.27.2/internal/handler/tenant.go#L360 github.com: https://github.com/infiniflow/ragflow vulncheck.com: https://www.vulncheck.com/advisories/ragflow-through-0.27.2-tenant-import-endpoints-path-traversal
Credits
Yu Sun VulnCheck