PT-2026-53165 · Ragapp · Ragapp

·

CVE-2026-13509

·

Published

2026-06-28

·

Updated

2026-06-29

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RAGapp versions prior to 0.1.6
Description A path traversal issue exists in the Knowledge File Handler component. This flaw allows remote attackers to manipulate files via the FileHandler.upload file() and FileHandler.remove file() functions located in the src/ragapp/backend/controllers/files.py file. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that reference files with input that is not properly neutralized.
Recommendations As a temporary workaround, restrict the use of the FileHandler.upload file() and FileHandler.remove file() functions until a patch is available.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13509

Affected Products

Ragapp