infiniflow has 3 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 8.8 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.8
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2025-69286Critical· 9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine66CVE-2025-68700High· 8.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine49CVE-2026-93013Medium· 4.3RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…24
infiniflow vulnerabilities
CVEs affecting infiniflow, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-93013Medium· 4.3RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…
RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in…
CVE-2025-69286Critical· 9.8PoCRAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows thes…
CVE-2025-68700High· 8.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the front…