THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75898 (HIGH 8.5) — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, re

[NVD] CVE-2026-75898 (HIGH 8.5) — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, re

mednvdPublished 2026-08-18

CVE-2026-75898 CVSS: 8.5 HIGH Published: 2026-08-18T15:17:15.367

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the share

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75898