CVE-2026-28797(infiniflow / ragflow)

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerability exists in RAGFlow's Agent workflow Text Processing (StringTransform) and Message components. These components use Python's jinja2.Template (unsandboxed) to render user-supplied templates, allowing any authenticated user to execute arbitrary operating system commands on the server. At time of publication, there are no publicly available patches.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ragflow

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
ragflow

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-16: 209-16
Full discourse2 posts
  • Clint Quah@DaddyQuah

    AI security isn't just about the model. The real attack surface includes the workflows, tools, APIs, credentials and runtime around it. RAGFlow shows why. CVE-2026-45312 and CVE-2026-28797 turned Jinja2 SSTI into remote code execution.

    0002047
    31 followersView on X
  • Six string shooter@one_blues_fan

    AI security isn't just about the model. The real attack surface includes the workflows, tools, APIs, credentials and runtime around it. RAGFlow shows why. CVE-2026-45312 and CVE-2026-28797 turned Jinja2 SSTI into remote code execution.

    0000032
    101 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinfiniflowragflow---

Explore more