CVE-2025-48187: Critical severity ragflow vulnerability
RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48187?
CVE-2025-48187 is a high-severity vulnerability due to its potential for account takeover through brute-force attacks.
How do I fix CVE-2025-48187?
To resolve CVE-2025-48187, implement rate limiting on email verification codes to prevent brute-force attempts.
Who is affected by CVE-2025-48187?
RAGFlow versions up to and including 0.18.1 are affected by CVE-2025-48187.
What type of attack does CVE-2025-48187 allow?
CVE-2025-48187 allows for brute-force attacks targeting email verification codes, leading to potential account registration and login exploitation.
What should users of RAGFlow do regarding CVE-2025-48187?
Users of RAGFlow should upgrade to a patched version and enforce strong security measures to prevent unauthorized account access.