PT-2026-53165 · Ragapp · Ragapp
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RAGapp versions prior to 0.1.6
Description
A path traversal issue exists in the Knowledge File Handler component. This flaw allows remote attackers to manipulate files via the
FileHandler.upload file() and FileHandler.remove file() functions located in the src/ragapp/backend/controllers/files.py file. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.Recommendations
As a temporary workaround, restrict the use of the
FileHandler.upload file() and FileHandler.remove file() functions until a patch is available.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ragapp