CVE-2025-69286
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm in the API key and beta (assistant/agent share auth) token generation process allows these tokens to be mutually derivable. Specifically, both tokens are generated using the same `URLSafeTimedSerializer` with predictable inputs, enabling an unauthorized user who obtains the shared assistant/agent URL to derive the personal API key. This grants them full control over the assistant/agent owner's account. Version 0.22.0 fixes the issue.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.9
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.77%
- CWE
- CWE-340
- Published
- 2025-12-31
- Last modified
- 2026-03-13
Affected products
- infiniflow ragflow
Weakness type
Related vulnerabilities
- CVE-2026-64964 — Generation of Predictable Email Confirmation Token in ATutor
- CVE-2025-14602 — Weak File Name Generation in vsDesk
- CVE-2026-75106 — OpnForm Editable Submission Secret Derivation via Empty Hashids Salt
- CVE-2026-13577 — Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable
- CVE-2026-47085 — An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can...
- CVE-2026-56016 — CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources
- CVE-2026-9219 — Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers
- CVE-2026-11374 — Account Takeover via Predictable SSO Ticket Generation