Vulnerabilities & PatchesEmerging1 src
CVE-2026-75898 - RAGFlow 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
CVE ID : CVE-2026-75898
Published : Aug. 18, 2026, 2:24 p. m.
• 44 minutes ago
Description : RAGFlow before 0. 26. 3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke. py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests. get, requests. post, or requests.
put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike the crawler, SearXNG, file-upload, and RSS fetch paths.
A user who can create or trigger an agent can direct the server to fetch loopback, link-local, and RFC 1918 destinations, including cloud instance metadata endpoints and services co-located on the deployment network, and the response body is returned as the component output.