CVE-2025-69286 - CVE House
Back to Database
Status published High CVE-2025-69286

RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

Vulnerability Description

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them full control over the assistant/agent owner's account. Version 0.22.0 fixes the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-69286

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

ragflow
Vulnerable Versions:
< 0.22.0

Timeline

Official Publish: December 31st, 2025
Last Modified: January 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.