Impact
RAGFlow up to version 0.27.2 contains a path traversal flaw in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints. An authenticated user can supply an absolute file_path parameter, causing the application to read and return the contents of any file that the service can access, provided the file contains a JSON structure that can be written into a dataset. The vulnerability therefore allows sensitive file contents to be exfiltrated by an attacker with valid credentials.
Affected Systems
The flaw is present in the infiniflow:ragflow product versions up to and including 0.27.2. No further version details are provided beyond the indication that the issue exists in the 0.27.2 release. The identifiers supplied by the CNA confirm that the vulnerability affects all builds of this publicly available RAGFlow application.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires a valid access token, so it is an authenticated path traversal vector. Because the read is limited to JSON files that can be ingested into datasets, the impact is confined to information disclosure rather than arbitrary code execution. The moderate CVSS score combined with the lack of publicly available exploitation data suggests a relatively low likelihood of immediate exploitation, but the confidentiality consequences warrant prompt attention.
OpenCVE Enrichment