CVE-2025-69286: RAGFlow has Predictable Token Generation Leading to Authentication Bypass Vulnerability

Published Dec 31, 2025
·
Updated

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same URLSafeTimedSerializer with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them full control over the assistant/agent owner's account. Version 0.22.0 fixes the issue.

Affected Software

2 affected components
RAGFlow<0.22.0
infiniflow ragflow<0.22.0

Event History

Dec 31, 2025
CVE Published
via MITRE·09:52 PM
Data Sourced
via MITRE·09:52 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 12, 57986
Event
via NVD·08:59 AM

Frequently Asked Questions

1

What is the severity of CVE-2025-69286?

CVE-2025-69286 has been classified with a moderate severity due to the potential exposure of API keys and tokens.

2

How do I fix CVE-2025-69286?

To remediate CVE-2025-69286, upgrade RAGFlow to version 0.22.0 or later.

3

What versions are affected by CVE-2025-69286?

CVE-2025-69286 affects RAGFlow versions prior to 0.22.0.

4

What is the root cause of CVE-2025-69286?

The root cause of CVE-2025-69286 is the use of an insecure key generation algorithm for API and token generation.

5

What impact does CVE-2025-69286 have on security?

CVE-2025-69286 allows tokens to be mutually derivable, which can lead to unauthorized access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203