Description
RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

RAGFlow up to version 0.27.2 contains a path traversal flaw in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints. An authenticated user can supply an absolute file_path parameter, causing the application to read and return the contents of any file that the service can access, provided the file contains a JSON structure that can be written into a dataset. The vulnerability therefore allows sensitive file contents to be exfiltrated by an attacker with valid credentials.

Affected Systems

The flaw is present in the infiniflow:ragflow product versions up to and including 0.27.2. No further version details are provided beyond the indication that the issue exists in the 0.27.2 release. The identifiers supplied by the CNA confirm that the vulnerability affects all builds of this publicly available RAGFlow application.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attack requires a valid access token, so it is an authenticated path traversal vector. Because the read is limited to JSON files that can be ingested into datasets, the impact is confined to information disclosure rather than arbitrary code execution. The moderate CVSS score combined with the lack of publicly available exploitation data suggests a relatively low likelihood of immediate exploitation, but the confidentiality consequences warrant prompt attention.

Generated by OpenCVE AI on September 17, 2026 at 21:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a version of RAGFlow released after 0.27.2 that incorporates the path traversal fix.
  • Add input validation to the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints to reject absolute file paths and restrict file_path to a whitelisted directory.
  • Ensure that only users with the lowest necessary privileges can invoke the tenant import endpoints to reduce the potential impact of an authenticated attack.

Generated by OpenCVE AI on September 17, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description RAGFlow through 0.27.2 contains a path traversal vulnerability in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the file_path parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.
Title RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal
First Time appeared Infiniflow
Infiniflow ragflow
Weaknesses CWE-22
CPEs cpe:2.3:a:infiniflow:ragflow:*:*:*:*:*:*:*:*
Vendors & Products Infiniflow
Infiniflow ragflow
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Infiniflow Ragflow
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:47:39.278Z

Reserved: 2026-09-17T14:45:52.522Z

Link: CVE-2026-93013

cve-icon Vulnrichment

Updated: 2026-09-21T20:47:34.211Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:18:35.483

Modified: 2026-09-21T21:17:17.423

Link: CVE-2026-93013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:45:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')