CVE-2026-51897: RAGFlow RAGFlow vulnerability
Published Oct 1, 2026
·Updated
RAGFlow 0.24.0 contains improper access control in getdataset (api/apps/evaluationapp). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution
Affected Software
1 affected component
RAGFlow RAGFlow=0.24.0
Event History
Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments running RAGFlow 0.24.0 may be affected where the get_dataset functionality in api/apps/evaluation_app is exposed to an attacker.
2
What does an attacker need to exploit the vulnerability?
The attacker needs access to an exposed entry point that reaches get_dataset in api/apps/evaluation_app. The available data does not specify whether authentication or particular privileges are required.
3
What is the potential impact of successful exploitation?
Depending on the exposed entry point, an attacker may be able to trigger execution of attacker-controlled code or commands.