---
cve: "CVE-2025-27135"
severity: "HIGH"
cvss: 8.9
epss: "0.6%"
vendor: "infiniflow"
kev: false
exploited: false
published: "2025-02-25 18:16:58"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-23T12:58:37+02:00"
---

# CVE-2025-27135

> 8.9 HIGH · 🧪 PoC

## Beschreibung

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL component extracts the SQL statement from the input and sends it directly to the database query. As of time of publication, no patched version is available.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://github.com/infiniflow/ragflow/security/advisories/GHSA-3gqj-66qm-25jq>
- <https://github.com/infiniflow/ragflow/blob/v0.15.1/agent/component/exesql.py>
- <https://swizzky.notion.site/ragflow-exesql-150ca6df7c03806989cefde915cf8e42?pvs=4>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-27135) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
