In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, allowing attackers to read server files. Furthermore, the use of an outdated Chromium headless version with --no-sandbox mode enabled makes the application susceptible to Remote Code Execution (RCE) via known Chromium v8 vulnerabilities. These issues are resolved in version 0.14.0.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Apr 2025 09:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 |
Tue, 01 Apr 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infiniflow
Infiniflow ragflow |
|
Weaknesses | CWE-918 | |
CPEs | cpe:2.3:a:infiniflow:ragflow:0.12.0:*:*:*:*:*:*:* | |
Vendors & Products |
Infiniflow
Infiniflow ragflow |
|
Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, allowing attackers to read server files. Furthermore, the use of an outdated Chromium headless version with --no-sandbox mode enabled makes the application susceptible to Remote Code Execution (RCE) via known Chromium v8 vulnerabilities. These issues are resolved in version 0.14.0. | |
Title | RCE, Full Read SSRF, and Arbitrary File Read in infiniflow/ragflow | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:11:05.133Z
Updated: 2025-04-04T08:45:39.429Z
Reserved: 2024-12-10T19:21:52.795Z
Link: CVE-2024-12450

Updated: 2025-03-20T15:22:43.103Z

Status : Modified
Published: 2025-03-20T10:15:28.883
Modified: 2025-04-04T09:15:15.207
Link: CVE-2024-12450

No data.