CVE-2026-28797 is a server-side template injection vulnerability in RAGFlow versions 0.24.0 and earlier. The Agent workflow Text Processing (StringTransform) and Message components render user-supplied templates using Python's unsandboxed jinja2.Template. An authenticated user can supply a crafted Jinja2 template that escapes intended template constraints and invokes arbitrary operating-system commands in the RAGFlow server process context.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python audit/exploitation tool for three RAGFlow vulnerabilities. It contains a README with usage and vulnerability background plus a single executable script, `ragflow-audit.py`, implemented entirely with Python standard library modules (`argparse`, `urllib`, `zipfile`, etc.). The script exposes three subcommands: 1. `ssti`: an authenticated web exploit for CVE-2026-28797. It builds a malicious RAGFlow canvas DSL targeting either the `StringTransform` or `Message` component, submits it to `/v1/canvas/set`, then triggers execution via `/v1/canvas/completion`. The embedded Jinja2 payload runs `os.popen("id")` on the server. Success is determined by parsing the response for `uid=`. A newline-based alternate payload is included to bypass a regex-based filter. 2. `zipslip`: an offline detector for CVE-2026-24770. It does not exploit a remote service directly; instead it inspects ZIP entries for traversal (`..`), absolute paths, and symlink entries that could lead to Zip Slip during extraction. 3. `apikey`: a helper for CVE-2025-69286. It decodes a share `beta` token, attempts to recover the UUID body, then brute-forces candidate `time_low` values to generate possible `ragflow-...` API tokens. The script does not automatically validate candidates against a live target, but the README and comments explain that real exploitation would test each candidate token against authenticated API endpoints and distinguish success by HTTP 200 vs 401. Overall, this is a real exploit/audit utility rather than a framework module. Its strongest capability is authenticated SSTI-to-RCE against vulnerable RAGFlow instances. The ZIP functionality is detection-only and local. The API-key functionality is an operational derivation aid but stops short of full automated online exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authenticated Jinja2 server-side template-injection vulnerability in RAGFlow Agent workflow components. The article lists it as possible context but does not attribute the observed RAGFlow intrusion to it.
An authenticated Jinja2 server-side template-injection vulnerability in RAGFlow Agent workflow components, referenced as possible technical context rather than a confirmed cause of the observed compromise.
Server-Side Template Injection (SSTI) vulnerability in RAGFlow that allows any authenticated user to achieve remote code execution on the server.
A server-side template injection vulnerability in RAGFlow versions 0.24.0 and prior that allows any authenticated user to execute arbitrary operating system commands on the server via unsandboxed jinja2.Template usage in Agent workflow Text Processing (StringTransform) and Message components.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.