


Perceptive Security
SOC/SIEM Consultancy

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/g…
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 14:01:48
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Emerging Technologies
RAGFlow, an open-source Retrieval-Augmented Generation engine, contains a critical Server-Side Template Injection (SSTI) vulnerability in versions 0.24.0 and earlier. The vulnerability exists in the Jinja2 template injection within the prompt generator component (rag/prompts/generator.py). Any authenticated user can exploit this flaw to execute arbitrary operating system commands on the server. The attack can be triggered by creating a Canvas workflow with a DuckDuckGo + LLM component chain, making this a high-severity vulnerability that allows for remote code execution with minimal user privileges required.
Technical details
Mitigation steps:
Affected products:
RAGFlow
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-45312
https://github.com/infiniflow/ragflow/security/advisories/GHSA-wpg4-h5g2-jxm6
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
