CVE-2025-25282
CVSS 3.0 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-25282 is a newly identified vulnerability affecting the RAGFlow open-source Retrieval-Augmented Generation engine. This issue involves an Insecure Direct Object Reference (IDOR) vulnerability that allows authenticated users to access data from other tenants, potentially leading to unauthorized cross-tenant access. Specifically, users can list user accounts from other tenants using the GET /<tenant_id>/user/list request and add user accounts to other tenants via a POST /<tenant_id>/user request. At this time, a patch for this vulnerability has not been released. Users are urged to contact the project maintainers to coordinate a fix and secure their tenants against unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.