CVE-2025-68700 - CVE House
Back to Database
Status published High CVE-2025-68700

RAGFlow Remote Code Execution Vulnerability

Vulnerability Description

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host process via the frontend Canvas CodeExec component, completely bypassing sandbox isolation. This occurs because untrusted data (stdout) is parsed using eval() with no filtering or sandboxing. The intended design was to "automatically convert string results into Python objects," but this effectively executes attacker-controlled code. Additional endpoints lack access control or contain inverted permission logic, significantly expanding the attack surface and enabling chained exploitation. Version 0.23.0 contains a patch for the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68700

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ragflow
Vulnerable Versions:
< 0.23.0

Timeline

Official Publish: December 31st, 2025
Last Modified: January 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)