CVE-2026-93013: RAGFlow through 0.27.2 Tenant Import Endpoints Path Traversal

Published Sep 17, 2026
·
Updated

RAGFlow through 0.27.2 contains a path traversal vulnerability in the devinsertchunksfromfile and devinsertmetadatafromfile endpoints that allows authenticated attackers to read arbitrary files by supplying absolute file paths in the filepath parameter. Attackers with valid access tokens can exploit missing path validation to read any file accessible to the service, with disclosure limited to files matching expected JSON structures that are then written to datasets.

Affected Software

1 affected component
RAGFlow<=0.27.2

Event History

Sep 17, 2026
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs a valid access token and access to the affected tenant import endpoints. It is not exploitable by an unauthenticated remote attacker based on the provided information.

2

What data could be exposed?

The attacker can request absolute paths and read files that are accessible to the RAGFlow service process. Disclosure is limited to files matching the expected JSON structures that the endpoints process and write into datasets.

3

Does this vulnerability allow modification or deletion of files?

The reported impact is limited to information disclosure. The supplied severity vector indicates no integrity or availability impact.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203