CVE-2026-51895: RAGFlow RAGFlow vulnerability
Published Oct 1, 2026
·Updated
Ragflow 0.24.0 and prior contains improper access control in updatemetadatasetting (api/apps/kbapp.py). Depending on the exposed entry, an attacker can perform unauthorized cross-session or privilege-crossing operations.
Affected Software
1 affected component
RAGFlow RAGFlow<=0.24.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
Which deployments are potentially affected?
Ragflow 0.24.0 and prior are identified as affected. Exposure depends on whether the relevant update_metadata_setting entry is accessible to an attacker.
2
What could an attacker do if the vulnerable entry is exposed?
An attacker may be able to perform unauthorized operations across sessions or cross privilege boundaries due to improper access control in update_metadata_setting.