{"api_version":"v1","generated_at":"2026-10-08T15:55:00+00:00","product":{"cve_count":10,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-infiniflow-ragflow-1e3989feaf15","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"RAGFlow","next_cursor":null,"observations":[{"affected":"ragflow: \u2264 0.27.2","affected_versions_present":true,"cve_id":"CVE-2026-93013","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-93013","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-21T20:47:39.278Z","patch_url":"","primary_source":"","published":"2026-09-17T15:16:51.432Z"},{"affected":"ragflow: < 0.26.3","affected_versions_present":true,"cve_id":"CVE-2026-75898","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-75898","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:19:31.557Z","patch_url":"","primary_source":"","published":"2026-08-18T14:24:06.089Z"},{"affected":"< 0.26.3","affected_versions_present":true,"cve_id":"CVE-2026-58579","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-58579","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T22:03:19.038Z","patch_url":"","primary_source":"","published":"2026-07-02T19:38:51.314Z"},{"affected":"<= 0.24.0","affected_versions_present":true,"cve_id":"CVE-2026-45312","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45312","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-02T01:02:42.683Z","patch_url":"","primary_source":"","published":"2026-05-29T12:24:07.996Z"},{"affected":"<= 0.24.0","affected_versions_present":true,"cve_id":"CVE-2026-28797","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-28797","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-06T18:57:26.934Z","patch_url":"https://github.com/infiniflow/ragflow/security/advisories/GHSA-vvwj-fvwh-4whx","primary_source":"","published":"2026-04-03T21:41:54.291Z"},{"affected":"<= 0.23.1","affected_versions_present":true,"cve_id":"CVE-2026-24770","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-24770","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-28T21:11:58.921Z","patch_url":"https://github.com/infiniflow/ragflow/commit/64c75d558e4a17a4a48953b4c201526431d8338f","primary_source":"","published":"2026-01-27T21:51:44.874Z"},{"affected":"ragflow: < 0.22.0","affected_versions_present":true,"cve_id":"CVE-2025-69286","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69286","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-02T14:35:31.041Z","patch_url":"https://github.com/infiniflow/ragflow/commit/a3bb4aadcc3494fb27f2a9933b4c46df8eb532e6","primary_source":"","published":"2025-12-31T21:52:54.304Z"},{"affected":"ragflow: < 0.23.0","affected_versions_present":true,"cve_id":"CVE-2025-68700","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68700","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-02T14:35:48.551Z","patch_url":"https://github.com/infiniflow/ragflow/commit/7a344a32f9f83529e12ca12f40f2657eb79fe811","primary_source":"","published":"2025-12-31T21:17:40.480Z"},{"affected":"\u2264 0.18.1","affected_versions_present":true,"cve_id":"CVE-2025-48187","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-48187","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-05-19T15:56:53.263Z","patch_url":"https://github.com/infiniflow/ragflow/commits/main/","primary_source":"","published":"2025-05-17T00:00:00.000Z"},{"affected":"<= 0.15.1","affected_versions_present":true,"cve_id":"CVE-2025-27135","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27135","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-25T18:57:33.672Z","patch_url":"","primary_source":"","published":"2025-02-25T18:16:58.667Z"},{"affected":"<= 0.13.0","affected_versions_present":true,"cve_id":"CVE-2025-25282","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-25282","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-24T14:49:12.014Z","patch_url":"","primary_source":"","published":"2025-02-21T21:04:34.731Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"infiniflow"}}
