generated: '2026-08-27' method: probed source: https://github.com/infiniflow/ragflow/security/policy + https://github.com/infiniflow/ragflow/security/advisories summary: >- RAGFlow runs its vulnerability disclosure entirely on GitHub. Private vulnerability reporting is ENABLED on the repository (confirmed via the GitHub API), a security policy page is served, and InfiniFlow has published multiple credited security advisories with CVE-class severities. There is no security.txt, no bug bounty, and no security page on ragflow.io. program: published: true channel: GitHub Security Advisories private_reporting_enabled: true private_reporting_evidence: url: https://api.github.com/repos/infiniflow/ragflow/private-vulnerability-reporting http_status: 200 body: '{"enabled":true}' policy_url: https://github.com/infiniflow/ragflow/security/policy policy_http_status: 200 advisories_url: https://github.com/infiniflow/ragflow/security/advisories advisories_http_status: 200 bug_bounty: false bug_bounty_platforms_checked: [HackerOne, Bugcrowd, Intigriti] security_txt: false security_txt_note: >- /.well-known/security.txt returns 404 on ragflow.io and an SPA HTML shell on cloud.ragflow.io and demo.ragflow.io. See well-known/ragflow-well-known.yml. contact_email: null contact_note: >- No security contact address is published anywhere. The only reporting path is the GitHub private advisory form. policy_file: path: SECURITY.md url: https://github.com/infiniflow/ragflow/blob/main/SECURITY.md http_status: 200 quality: poor finding: >- SECURITY.md is not a disclosure policy. It is the GitHub template with a pasted vulnerability REPORT left in the "Reporting a Vulnerability" section — a 2024-era restricted_loads / numpy.f2py deserialization RCE, complete with proof-of-concept code — and its "Supported Versions" table claims support only for versions <= 0.7.0, while the current release is 0.27.0. It names no contact, no response SLA and no coordinated-disclosure window. The functioning channel is GitHub's private reporting form, which the file does not mention. recommended_fix: >- Replace SECURITY.md with an actual policy: a reporting address or a pointer to the private advisory form, a supported-version table that matches the current release train, an acknowledgement target and a disclosure timeline. Serve a /.well-known/security.txt on ragflow.io and cloud.ragflow.io pointing at it. published_advisories: count_sampled: 7 note: The seven most recent advisories returned by the GitHub API on 2026-08-27. advisories: - id: GHSA-wpg4-h5g2-jxm6 severity: critical summary: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution - id: GHSA-vvwj-fvwh-4whx severity: critical summary: Server-Side Template Injection (SSTI) leading to RCE in Agent "Text Processing" Component - id: GHSA-v7cf-w7gj-pgf4 severity: critical summary: '[RF-01] Zip Slip Remote Code Execution (RCE) in MinerUParser' - id: GHSA-8xw3-v6c2-j84j severity: high summary: RAGFlow Remote Code Execution Vulnerability - id: GHSA-9j5g-g4xm-57w7 severity: critical summary: Predictable Token Generation Leading to Authentication Bypass Vulnerability - id: GHSA-3gqj-66qm-25jq severity: critical summary: SQL injection vulnerability in ragflow - id: GHSA-wc5v-g79p-7hch severity: high summary: Potential Insecure Direct Object Reference (IDOR) vulnerability in ragflow assessment: >- A live, used disclosure channel — advisories are written up, severity-rated and published rather than fixed silently. That is the substance of a disclosure program; what is missing is the front door that tells a reporter where to knock. x-evidence: - url: https://github.com/infiniflow/ragflow/security/policy http_status: 200 - url: https://github.com/infiniflow/ragflow/security/advisories http_status: 200 - url: https://ragflow.io/.well-known/security.txt http_status: 404 - url: https://ragflow.io/security http_status: 404