Skip to content

There is an SQL injection vulnerability in ragflow.

Critical
KevinHuSh published GHSA-3gqj-66qm-25jq Feb 25, 2025

Package

No package listed

Affected versions

<= v0.15.1

Patched versions

None

Description

Severity

Critical

CVE ID

CVE-2025-27135

Weaknesses

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Learn more on MITRE.

Credits