CVE-2025-48187

CRITICAL

Infiniflow Ragflow < 0.18.1 - Brute Force

Title source: rule
STIX 2.1

Description

RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.

Scores

CVSS v3 9.1
EPSS 0.0030
EPSS Percentile 53.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-307
Status published
Products (1)
infiniflow/ragflow < 0.18.1
Published May 17, 2025
Tracked Since Feb 18, 2026