
🚨 CVE-2026-24770: RAGFlow RCE (Zip Slip) Weaponized PoC Critical unauthenticated RCE in RAGFlow’s MinerUParser—attackers can execute arbitrary commands. 3,000+ instances are currently exposed. 🔥 PoC ready for download! Celebrate our CVE Feed launch with a $5 Special Trial to get the PoC instantly: 👉 https://www.darkeye.org/vuln/cve/CVE-2026-24770 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-24770" Dork: app="RAGFlow" 👉 ZoomEye Search Link https://www.zoomeye.ai/searchResult?q=dnVsLmN2ZT0iQ1ZFLTIwMjYtMjQ3NzAi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260209 #Infosec #BugBounty #RAGFlow #RCE #DarkEye
Post summary
The tweet announces CVE‑2026‑24770, a critical unauthenticated RCE in RAGFlow, and offers a downloadable PoC, but does not mention active exploitation, patches, or debunking.





