CVE Tools

CVE-2026-28797

RAGFlow: Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in Agent "Text Processing" Component

No known exploitation. EPSS puts it in the 44th percentile. Only a workaround so far.

Published Updated Sources: CVE.org, NVD

What to do

No fixed build is published yet. The vendor describes a workaround.

Steps

Written by AI from the record
  1. Check whether your deployment uses RAGFlow and whether its version is 0.24.0 or earlier.
  2. Verify which accounts (and authentication method) can access the Agent workflow “Text Processing” / template-like features.
  3. If you are affected and no patch is available for your version, immediately restrict access so only the minimum trusted accounts can reach RAGFlow (and especially the Agent workflow endpoints involved).
  4. If possible in your setup, disable or remove the Agent “Text Processing” workflow (StringTransform) and any Message/template rendering functionality until a fixed version is available.
  5. Re-check after any vendor update or rebuild whether a fixed release exists for your exact RAGFlow version branch, and upgrade as soon as a patch becomes available.

What it is

From the CVE record

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary operating system commands on the server. At time of publication, there are no publicly available patches.

In plain language

Written by AI from the record

CVE-2026-28797 is a RAGFlow bug where an authenticated user can inject instructions into a template feature and cause the server to run commands; small businesses running RAGFlow (especially older versions up to 0.24.0) should treat this as actively dangerous.

In RAGFlow, an authenticated Server-Side Template Injection (SSTI) in the Agent “Text Processing” (StringTransform) and Message components lets a user supply a template that is rendered by unsandboxed jinja2.Template, enabling Remote Code Execution (RCE) on the server.

If you're affected

  • Server takeover via command execution
  • Data theft from the RAGFlow host
  • Ransomware risk from full compromise
  • Service disruption and downtime

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS44th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

0.6% chance of exploitation activity in the next 30 days, which ranks it in the 44th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

7 events over 112 days, from the signal feeds we watch.

  1. Workaround availablerecord updated
  2. Workaround availablerecord updated
  3. Publishedweakness classified, att&ck mapped

Affected products

Technical detail

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Scored 8.8 by NVD.

How it is reached

  • Attack Vector NetworkExploitable remotely over the network without any special conditions
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required LowRequires basic user-level privileges
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality HighTotal information disclosure — all data in the component is compromised
  • Integrity HighTotal loss of integrity — attacker can modify any data in the component
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Ragflow, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store