Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-45312: RAGFlow Jinja2 template injection enables remote code execution

A server-side template injection flaw in RAGFlow's prompt generator (rag/prompts/generator.py) in versions 0.24.0 and earlier lets any authenticated user run arbitrary OS commands on the server. Exploitation requires only registering an account and building a Canvas workflow chaining a DuckDuckGo search and LLM component to trigger the SSTI.

Disclosed 29 May 2026 · Record updated 13 September 2026

Impact

Any authenticated user of an affected RAGFlow instance could execute arbitrary operating system commands on the server hosting the RAG engine.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45312