RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Thu, 10 Jul 2025 22:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Infiniflow
Infiniflow ragflow |
|
CPEs | cpe:2.3:a:infiniflow:ragflow:0.13.0:*:*:*:*:*:*:* | |
Vendors & Products |
Infiniflow
Infiniflow ragflow |
Wed, 11 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
cvssV3_1
|
Mon, 09 Dec 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-09T00:00:00
Updated: 2024-12-11T15:54:34.771Z
Reserved: 2024-11-20T00:00:00
Link: CVE-2024-53450

Updated: 2024-12-11T15:54:27.234Z

Status : Analyzed
Published: 2024-12-09T17:15:09.350
Modified: 2025-07-10T22:34:47.983
Link: CVE-2024-53450

No data.