CVE-2026-75898 is a server-side request forgery vulnerability affecting RAGFlow before version 0.26.3. The flaw is in the agent workflow "Invoke" component, implemented in agent/component/invoke.py, which constructs outbound request URLs from canvas configuration and runtime template variables and then issues requests through HTTP client methods without applying the shared URL safety validation used elsewhere in the product or pinning the resolved destination address. Because the component accepts attacker-influenced URL input and returns the fetched response body as component output, an attacker who can create or trigger an agent can cause the RAGFlow server to make arbitrary outbound requests to internal or otherwise restricted network locations, including loopback, link-local, private RFC 1918 ranges, cloud metadata services, and adjacent services reachable from the deployment environment. If the Invoke URL is configured to interpolate chat-query input, any user able to submit that query may be able to control the request destination.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file Python proof-of-concept repository demonstrates CVE-2026-75898, an SSRF flaw in InfiniFlow RAGFlow's Invoke workflow component in versions before 0.26.3. The core preserved source is target/invoke_v0.26.2.py, described as the unmodified RAGFlow v0.26.2 Invoke implementation. Its _build_url method only ensures an HTTP/HTTPS scheme, while _send_request passes the resulting user/template-controlled URL directly to requests.get, requests.post, or requests.put. It neither blocks private, loopback, or link-local addresses nor pins DNS resolution. Requests redirects remain enabled by default, permitting redirect chains into internal networks. The component places the fetched response text into the workflow result, creating an internal data-disclosure primitive. poc.py provides a CLI with a local --poc mode and an authenticated --check mode that attempts to create a malicious Invoke flow through several candidate RAGFlow API routes. e2e/test_genuine_ssrf.py loads the bundled Invoke source using minimal import stubs and proves direct loopback access and a 302 redirect to loopback, with simulated internal secrets returned to the caller. e2e/test_fix_guard.py is a comparison test that monkey-patches equivalent fixed behavior: private/loopback checks plus allow_redirects=False, and demonstrates that its local requests are blocked. README.md and LAB_DEMO.md document a claimed full Docker validation against RAGFlow v0.26.2, including authenticated agent execution and retrieval of a host-internal test secret. Despite poc.py's introductory 'pre-auth / low-priv' wording, its live check mode explicitly requires an authenticated session token; the supplied evidence supports an authenticated low-privileged workflow SSRF scenario rather than a pre-auth exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.