CVE-2025-25282 - RAGFlow IDOR: Cross-Tenant Access Vulnerability
CVE ID : CVE-2025-25282
Published : Feb. 21, 2025, 9:15 p.m. | 36 minutes ago
Description : RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts, add user account into other tenant). Unauthorized cross-tenant access: list user from other tenant (e.g., via GET //user/list), add user account to other tenant (POST //user). This issue has not yet been patched. Users are advised to reach out to the project maintainers to coordinate a fix.
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Feb. 21, 2025, 9:15 p.m. | 36 minutes ago
Description : RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Insecure Direct Object Reference (IDOR) vulnerability that may lead to unauthorized cross-tenant access (list tenant user accounts, add user account into other tenant). Unauthorized cross-tenant access: list user from other tenant (e.g., via GET /
Severity: 8.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...