CVE-2025-69286 is a predictable-token-generation vulnerability in RAGFlow versions before 0.22.0. RAGFlow generates personal API keys and beta assistant/agent sharing-authentication tokens with the same URLSafeTimedSerializer and predictable inputs, making the two token types mutually derivable. An unauthorized party that obtains a shared assistant or agent URL can derive the associated owner’s personal API key and take full control of that account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python audit/exploitation tool for three RAGFlow vulnerabilities. It contains a README with usage and vulnerability background plus a single executable script, `ragflow-audit.py`, implemented entirely with Python standard library modules (`argparse`, `urllib`, `zipfile`, etc.). The script exposes three subcommands: 1. `ssti`: an authenticated web exploit for CVE-2026-28797. It builds a malicious RAGFlow canvas DSL targeting either the `StringTransform` or `Message` component, submits it to `/v1/canvas/set`, then triggers execution via `/v1/canvas/completion`. The embedded Jinja2 payload runs `os.popen("id")` on the server. Success is determined by parsing the response for `uid=`. A newline-based alternate payload is included to bypass a regex-based filter. 2. `zipslip`: an offline detector for CVE-2026-24770. It does not exploit a remote service directly; instead it inspects ZIP entries for traversal (`..`), absolute paths, and symlink entries that could lead to Zip Slip during extraction. 3. `apikey`: a helper for CVE-2025-69286. It decodes a share `beta` token, attempts to recover the UUID body, then brute-forces candidate `time_low` values to generate possible `ragflow-...` API tokens. The script does not automatically validate candidates against a live target, but the README and comments explain that real exploitation would test each candidate token against authenticated API endpoints and distinguish success by HTTP 200 vs 401. Overall, this is a real exploit/audit utility rather than a framework module. Its strongest capability is authenticated SSTI-to-RCE against vulnerable RAGFlow instances. The ZIP functionality is detection-only and local. The API-key functionality is an operational derivation aid but stops short of full automated online exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An account-access weakness affecting RAGFlow that could influence access to authenticated functionality depending on deployment configuration. It is not attributed as the exploitation vector in this incident.
An account-access weakness in RAGFlow that may affect access to authenticated functionality, depending on deployment configuration. The content does not identify it as the confirmed cause of the incident.
A predictable token generation vulnerability in RAGFlow prior to version 0.22.0 allows authentication bypass and full account takeover by deriving API keys from assistant/agent share URLs.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.