---
id: CVE-2026-51897
title: >-
  RAGFlow 0.24.0 contains improper access control in get_dataset
  (api/apps/evaluation_app)
summary: >-
  RAGFlow 0.24.0 contains improper access control in get_dataset
  (api/apps/evaluation_app). Depending on the exposed entry, an attacker can
  trigger attacker-controlled code or command execution
severity: none
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:04.267'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51897'
references:
  - url: 'https://gist.github.com/Ro1ME/7101a09720c120fd4989705aa7c0b894'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T23:03:32.778Z'
---

## Overview

RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
