CVE-2026-93013: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in infiniflow ragflow
RAGFlow versions up to 0.27.2 contain a path traversal vulnerability in two endpoints that allows authenticated users to read arbitrary files by providing absolute file paths. The vulnerability affects the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints. Exploitation requires valid access tokens and the ability to supply file paths. The disclosed files are limited to those matching expected JSON structures that the service processes into datasets.
AI Analysis
Technical Summary
CVE-2026-93013 is a path traversal vulnerability in infiniflow's RAGFlow product, affecting versions up to and including 0.27.2. Authenticated attackers with valid access tokens can exploit missing validation on the file_path parameter in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints to read arbitrary files accessible to the service. The vulnerability allows reading files by supplying absolute file paths, but disclosure is constrained to files that match expected JSON structures processed by the service.
Potential Impact
An attacker with valid credentials can read arbitrary files on the system that the service has access to, potentially exposing sensitive data. However, the impact is limited by the requirement that the files must match expected JSON structures to be processed and disclosed. There is no indication of privilege escalation, remote code execution, or denial of service from this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected endpoints to trusted users only and monitor for suspicious activity involving file_path parameters. Implement additional input validation or filtering on file paths if possible.
CVE-2026-93013: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in infiniflow ragflow
Description
RAGFlow versions up to 0.27.2 contain a path traversal vulnerability in two endpoints that allows authenticated users to read arbitrary files by providing absolute file paths. The vulnerability affects the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints. Exploitation requires valid access tokens and the ability to supply file paths. The disclosed files are limited to those matching expected JSON structures that the service processes into datasets.
CVSS v4.0
Score 5.3medium
Affected software
infiniflow
ragflow
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-93013 is a path traversal vulnerability in infiniflow's RAGFlow product, affecting versions up to and including 0.27.2. Authenticated attackers with valid access tokens can exploit missing validation on the file_path parameter in the dev_insert_chunks_from_file and dev_insert_metadata_from_file endpoints to read arbitrary files accessible to the service. The vulnerability allows reading files by supplying absolute file paths, but disclosure is constrained to files that match expected JSON structures processed by the service.
Potential Impact
An attacker with valid credentials can read arbitrary files on the system that the service has access to, potentially exposing sensitive data. However, the impact is limited by the requirement that the files must match expected JSON structures to be processed and disclosed. There is no indication of privilege escalation, remote code execution, or denial of service from this vulnerability.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the affected endpoints to trusted users only and monitor for suspicious activity involving file_path parameters. Implement additional input validation or filtering on file paths if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-17T14:45:52.522Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac080b55bf5e2cf5909ac0
Added to database: 09/17/2026, 15:32:27 UTC
Last enriched: 09/17/2026, 15:46:55 UTC
Last updated: 09/17/2026, 15:46:55 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.