9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user to execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the SSTI.
AI Analysis
Server-Side Template Injection in Prompt Generator leads to Remote Code Execution
Basic Information
ID
CVE-2026-45312
Source
GitHub_M
Published
May 29, 2026 at 12:24
Affected Product
Vendor
infiniflow
Product
ragflow
Version
<= 0.24.0
Affected Versions
infiniflow ragflow <= 0.24.0
CWE Classification
AI Assessment
AI Score
9.9 / 10
AI Severity
Critical
Vendor
infiniflow
Product
RAGFlow
Version
0.24.0 and earlier