logo

CVE-2026-45312 | infiniflow RAGFlow up to 0.24.0 rag/prompts/generator.py special elements used in a template engine

ID: 882f8047-86db-56c6-baf6-bd221b5e485c

STIX ID: report--882f8047-86db-56c6-baf6-bd221b5e485c

Feed Name: VulDB Recent Entries

Threat Score
75/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

RAGFlow (≤0.24.0) has a critical Jinja2 template injection vulnerability in rag/prompts/generator.py (CVE-2026-45312) enabling authenticated — including self-registered — users to execute arbitrary OS commands remotely; technical details are known and exploitation appears easy, but no public exploit is available as of 05/29/2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.