CVE-2025-1546
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Feb 21, 2025
CWE ID 78
CWE ID 77
Summary
CVE-2025-25282 is a newly identified vulnerability affecting the open-source RAGFlow RAG (Retrieval-Augmented Generation) engine. The issue involves an Insecure Direct Object Reference (IDOR) issue that allows authenticated users to access data from other tenants, potentially resulting in unauthorized cross-tenant access. This vulnerability can enable users to list tenant user accounts and even add user accounts to other tenants. Although a fix has yet to be released, users are urged to contact the project maintainers to coordinate a solution.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share