CVE-2026-51892

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.

https://gist.github.com/Ro1ME/00684720b33e37b2dd39856d6c226468
https://github.com/infiniflow/ragflow/issues/14618
https://github.com/infiniflow/ragflow/issues/15267