CVE-2025-51462: XSS
Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialogapp.setdialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary JavaScript via crafted input to the assistant greeting field, which is stored unsanitised and rendered using a markdown component with rehype-raw.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51462?
CVE-2025-51462 is classified as a critical severity vulnerability due to its potential for remote code execution through stored cross-site scripting.
How do I fix CVE-2025-51462?
To fix CVE-2025-51462, update to the latest version of RAGFlow where the vulnerability has been patched.
Who is affected by CVE-2025-51462?
Users of RAGFlow version 0.17.2 are affected by CVE-2025-51462, particularly those utilizing the assistant greeting feature.
What type of vulnerability is CVE-2025-51462?
CVE-2025-51462 is a stored cross-site scripting (XSS) vulnerability allowing attackers to inject arbitrary JavaScript.
What impact does CVE-2025-51462 have?
CVE-2025-51462 can lead to unauthorized actions performed on behalf of users and exposure of sensitive data.