{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ragflow/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.5,"id":"CVE-2026-75898"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RAGFlow (0.26.2)"],"_cs_severities":["high"],"_cs_tags":["ssrf","vulnerability","cloud-security"],"_cs_type":"advisory","_cs_vendors":["RAGFlow"],"content_html":"\u003cp\u003eRAGFlow before version 0.26.3 is susceptible to a server-side request forgery (SSRF) vulnerability located in the agent workflow \u0026quot;Invoke\u0026quot; component (agent/component/invoke.py). The vulnerability stems from improper validation of user-controlled URLs before they are passed to request methods (requests.get, requests.post, or requests.put). Unlike other components in the system such as the crawler or file-upload paths, the Invoke component fails to utilize the shared assert_url_is_safe validator or pin the resolved address. An attacker capable of creating or triggering an agent workflow can coerce the server to perform requests against loopback interfaces, link-local addresses, and RFC 1918 internal networks. This includes the ability to exfiltrate data from cloud instance metadata services (e.g., AWS IMDS), as the response body from the forged request is returned directly to the user as the component output.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the exfiltration of sensitive internal network data and cloud instance credentials. In cloud-hosted environments, attackers may query metadata endpoints to retrieve IAM roles or other configuration secrets, potentially leading to full cluster or cloud account compromise. The impact is significant because the application returns the forged request's response body directly to the attacker, facilitating easy data extraction.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade RAGFlow to version 0.26.3 or later immediately to patch the SSRF vulnerability in the agent/component/invoke.py file.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the host machine running RAGFlow to block requests to loopback (127.0.0.0/8) and private IP ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) unless explicitly required for known internal services.\u003c/li\u003e\n\u003cli\u003eConfigure cloud instances (e.g., EC2, GCP Compute) to require IMDSv2 with a session token requirement to mitigate credential exfiltration via SSRF.\u003c/li\u003e\n\u003cli\u003eAudit existing agent workflows for suspicious Invoke component configurations, specifically those pointing to internal endpoints or utilizing runtime template variables for URL construction.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T16:55:42Z","date_published":"2026-08-18T16:55:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ragflow-ssrf/","summary":"RAGFlow before 0.26.3 contains a server-side request forgery (SSRF) vulnerability in the 'Invoke' component that allows attackers to access sensitive internal network resources and cloud metadata.","title":"SSRF Vulnerability in RAGFlow Agent Workflow","url":"https://feed.craftedsignal.io/briefs/2026-08-ragflow-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - RAGFlow","version":"https://jsonfeed.org/version/1.1"}