CVE-2025-1546

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Feb 21, 2025
CWE ID 78
CWE ID 77

Summary

CVE-2025-25282 is a newly identified vulnerability affecting the open-source RAGFlow RAG (Retrieval-Augmented Generation) engine. The issue involves an Insecure Direct Object Reference (IDOR) issue that allows authenticated users to access data from other tenants, potentially resulting in unauthorized cross-tenant access. This vulnerability can enable users to list tenant user accounts and even add user accounts to other tenants. Although a fix has yet to be released, users are urged to contact the project maintainers to coordinate a solution.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share