VulnerabilityAnalyzed
CVE-2025-27135
Versions 0.15.1 and prior are vulnerable to SQL injection.
HIGH 8.9EPSS 0.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched version is available.
- CVSS 4.0
- 8.9 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- infiniflow/ragflow
- Source
- security-advisories@github.com
References
- https://github.com/infiniflow/ragflow/blob/v0.15.1/agent/component/exesql.pyProduct
- https://github.com/infiniflow/ragflow/security/advisories/GHSA-3gqj-66qm-25jqVendor Advisory
- https://swizzky.notion.site/ragflow-exesql-150ca6df7c03806989cefde915cf8e42?pvs=4Exploit
- https://swizzky.notion.site/ragflow-exesql-150ca6df7c03806989cefde915cf8e42Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.