← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 18, 2026 · 14:24via CVEFeed

CVE-2026-75898 - RAGFlow 0.26.3 - Server-Side Request Forgery via Agent Invoke Component

Brief

CVE ID : CVE-2026-75898

Published : Aug. 18, 2026, 2:24 p. m.

  • 44 minutes ago

Description : RAGFlow before 0.

  • 3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke. py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests. get, requests. post, or requests.

put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike the crawler, SearXNG, file-upload, and RSS fetch paths.

A user who can create or trigger an agent can direct the server to fetch loopback, link-local, and RFC 1918 destinations, including cloud instance metadata endpoints and services co-located on the deployment network, and the response body is returned as the component output.

Read more on CVEFeed