CVE Tools

SSTI в RAGFlow. Разбираем недавнюю CVE в популярном генеративном движке

Хакер (xakep.ru)By ret0x2A

PoC publicRAGFlow

Our summary

A proof-of-concept exploit has been published for CVE-2026-28797, a Server-Side Template Injection (SSTI) flaw in InfiniFlow's RAGFlow that enables remote code execution. The vulnerability affects versions up to and including 0.24.0, where insufficient sanitization of Jinja templates within AI agent data manipulation blocks allows any authenticated user to execute arbitrary server-side commands. With a CVSS 4.0 score of 8.7, this high-risk issue impacts a widely adopted open-source engine featuring over 87,000 GitHub stars. Administrators should upgrade to version 0.26.4 or later to mitigate the risk.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store