CVE-2025-25282

CVSS 3.0 Score 8.1 of 10 (high)

Details

Published Feb 21, 2025
Updated: Feb 24, 2025
CWE ID 639

Summary

CVE-2025-25282 is a newly identified vulnerability affecting the RAGFlow open-source Retrieval-Augmented Generation engine. This issue involves an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access data from other tenants, potentially leading to unauthorized cross-tenant access. Specifically, users can list user accounts from other tenants using the GET /<tenant_id>/user/list request and add user accounts to other tenants via a POST /<tenant_id>/user request. At this time, a patch for this vulnerability has not been released. Users are urged to contact the project maintainers to coordinate a fix and secure their tenants against unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share