Infiniflow Ragflow Stored Cross-Site Scripting Vulnerability

Vulnerability

A stored cross-site scripting vulnerability has been identified in Infiniflow Ragflow, specifically in the latest commit on the main branch. This vulnerability allows attackers to upload HTML or XML files containing arbitrary JavaScript payloads. The uploaded files are served with an 'application/xml' content type, which browsers automatically render. This could enable the execution of the injected JavaScript in the context of the user's browser, potentially allowing attackers to steal cookies and access user files and resources. The vulnerability is accessible to anyone with network access to the instance and does not require authentication.

Impact

Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.7
exploitability
5.8
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.