RAGFlow before 0.26.3 contains a server-side request forgery (SSRF) vulnerability in the 'Invoke' component that allows attackers to access sensitive internal network resources and cloud metadata.
PoC
RAGFlow
ssrf
vulnerability
cloud-security
2t
1c
updated