
🚨 HIGH SEVERITY: CVE-2026-75898 (CVSS 8.5) RAGFlow <0.26.3 vulnerable to SSRF in agent workflow Invoke component. Attackers can access internal networks, cloud metadata endpoints. Patch immediately to v0.26.3+ #CVE #Vulnerability #PatchNow https://t.co/lH2StaEALj
Post summary
RAGFlow versions below 0.26.3 suffer from an SSRF flaw that could expose internal networks and cloud metadata; a patch to v0.26.3+ is available and recommended for immediate deployment.

