THREAT OPS › Threat News › [NVD] CVE-2026-75898 (HIGH 8.5) — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, re
[NVD] CVE-2026-75898 (HIGH 8.5) — RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, re
CVE-2026-75898 CVSS: 8.5 HIGH Published: 2026-08-18T15:17:15.367
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the share
Indicators of compromise
- CVE-2026-75898cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75898