A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey authkey=binfiniflow-token4kevinhu which can be easily fetched by attackers to join the group communication without restrictions. Additionally, the server processes incoming data using pickle deserialization via pickle.loads()
on connection.recv()
, making it vulnerable to remote code execution. This issue is fixed in version 0.14.0.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ragflow | Infiniflow | 0.12.0 (including) | 0.14.0 (excluding) |