CVE-2025-48187

CRITICAL

RAGFlow <= 0.18.1 - Account Takeover via Brute-Force Attack on Email Verification Codes

Title source: llm
STIX 2.1

Description

RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to perform arbitrary account registration, login, and password reset. Codes are six digits and there is no rate limiting.

Scores

CVSS v3 9.1
EPSS 0.0049
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-307
Status published
Products (1)
infiniflow/ragflow < 0.18.1
Published May 17, 2025
Tracked Since Feb 18, 2026