Retrieval-augmented generation
Systems that feed retrieved documents or vector-search results into a model's context.
- All items
- 33
- Last 90 days
- 10
- Change
- -9%vs 11 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 1 |
| Dec 2025 | 0 |
| Jan 2026 | 1 |
| Feb 2026 | 3 |
| Mar 2026 | 4 |
| Apr 2026 | 2 |
| May 2026 | 6 |
| Jun 2026 | 2 |
| Jul 2026 | 2 |
| Aug 2026 | 1 |
| Sep 2026 | 8 |
| Oct 2026 | 1 |
33 items
A Security Meta-Model for Retrieval-Augmented Generation Systems
Oct 8, 2026InfoResearchPreprintSecurityResearchThe paper introduces a security meta-model for Retrieval-Augmented Generation (RAG) systems that links RAG surfaces, attacks, weaknesses, risks, and CIA impact. Built from an iterative analysis of 43 publications from 2023 to 2026, it is instantiated as a catalog that filters into a deployment-specific risk profile. The authors report an imbalance between attack-focused and defense-focused research, a concentration of threats at ingestion, and coverage gaps affecting output integrity.
Arxiv (cs.CR + cs.CL + cs.LG)CVE-2026-18875: IBM FTM for RedHat OpenShift RAG poisoning via unauthenticated upsert
Sep 23, 2026HighVulnerabilitySecurityCVE-2026-18875IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
NVD/CVE DatabaseCVE-2026-85709: LightRAG API server leaks raw Python exception text in error responses
Sep 22, 2026MediumVulnerabilitySecurityCVE-2026-85709LightRAG's API server, before version 1.5.5, returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py and lightrag_server.py. A network client that triggers an error can read server filesystem paths, database host, port, user and database names, language-model provider diagnostics, configuration details and library internals, and with URI-configured backends possibly connection strings containing credentials. The default unauthenticated configuration makes these responses reachable without credentials.
Fix: Fixed in 1.5.5.
NVD/CVE DatabaseCVE-2026-53557: SQLBot second-order SQL injection through Excel datasource tableName
Sep 17, 2026CriticalVulnerabilitySecurityCVE-2026-53557SQLBot, a Text-to-SQL system built on large language models and RAG, is affected prior to version 1.9.0. An authenticated user can submit a crafted sheet["tableName"] value through POST /api/v1/datasource/, which is stored without safe identifier handling. When the datasource is later removed via DELETE /api/v1/datasource/{id}, PostgreSQL executes the stored value in cleanup SQL, allowing COPY TO PROGRAM and arbitrary operating-system commands under the postgres process privileges inside the SQLBot container.
Fix: Fixed in version 1.9.0.
NVD/CVE DatabaseCVE-2026-53556: SQLBot SQL injection in previewData endpoint table_name exposes server files
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-53556SQLBot, a Text-to-SQL system built on large language models and RAG, is affected by CVE-2026-53556 before version 1.9.0. The POST /api/v1/datasource/previewData endpoint places the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can use a crafted table_name to call pg_read_file(), pg_read_binary_file() or pg_ls_dir() through a datasource pointed at the internal PostgreSQL service, reading filesystem content such as /etc/hosts and /etc/passwd, and potentially configuration, credentials and source code. In the default tested trusted loopback authentication configuration, the connection runs with PostgreSQL superuser privileges.
Fix: This issue is fixed in version 1.9.0.
NVD/CVE DatabaseCVE-2026-53555: SQLBot stored cross-site scripting through uploaded SVG assistant logo
Sep 17, 2026MediumVulnerabilitySecurityCVE-2026-53555SQLBot, a Text-to-SQL system built on large language models and RAG, stores uploaded image/svg+xml assistant UI logos without sanitizing embedded active content before version 1.9.0. An authenticated uploader can submit such a file through PATCH /api/v1/system/assistant/ui, and SQLBot serves it inline from the same origin via GET /api/v1/system/assistant/picture/{filename}. When another user loads the file, embedded JavaScript runs in the SQLBot web application context with access to the victim's session data and actions.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-53554: SQLBot arbitrary code execution through parseExcel upload endpoint
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-53554CVE-2026-53554 affects SQLBot, a Text-to-SQL system built on large language models and RAG, prior to 1.9.0. The POST /api/v1/datasource/parseExcel endpoint trusts attacker-controlled multipart filenames when choosing storage, and it writes uploaded content before spreadsheet parsing and validation finish. A crafted upload can plant a Python file in /opt/sqlbot/app/alembic/versions/ even when parsing fails and the endpoint returns an error. On the next startup or migration, Alembic imports that file and runs its module-level statements inside the SQLBot runtime.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseWhen the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applications
Sep 9, 2026InfoNewsSecurityResearchA practical pen-testing guide for generative AI, LLM and RAG applications argues that the security question has shifted from whether a model says something it should not to whether manipulated language can reach protected data or trigger unauthorized business actions. It recommends starting with an architecture walk-through that maps prompts, retrieval, tools, identities and logging, then treating prompt injection as a multi-turn campaign rather than a single-phrase test.
CSO OnlineTowards Trustworthy Retrieval Augmented Generation for Large Language Models: A Survey
Sep 5, 2026InfoResearchPeer-reviewedSecurityResearchThis survey reviews trustworthiness in Retrieval Augmented Generation (RAG) for large language models. The source text provided is limited to the bibliographic line (ACM Computing Surveys, Volume 58, Issue 15, Pages 1-36, November 2026) and does not include the article body, so no findings or methods can be reported.
ACM Digital Library (TOPS, DTRAP, CSUR)DP2-RAG: An Efficient Full-Process Differential Privacy Implementation in Retrieval-Augmented Generation
Aug 20, 2026InfoResearchPeer-reviewedResearchPrivacyDP2-RAG is a framework that adds end-to-end differential privacy to Retrieval-Augmented Generation, covering both the retrieval stage and the generation stage. It introduces Noise-Aware Retrieval with Correction (NARC), which enforces chunk-level DP with calibrated noise and ranking-bias correction, and the Dual Utility-Exponent Mechanism (DUEM), which provides token-level DP for generated surrogates. Evaluated on six benchmarks, it reduces privacy leakage by over 15% relative to strong baselines while keeping near-baseline Top-k retrieval accuracy.
IEEE Xplore (Security & AI Journals)CVE-2026-56273: Flowise path traversal in Faiss and SimpleStore vector store basePath parameter
Jul 8, 2026MediumVulnerabilitySecurityCVE-2026-56273CVE-2026-56273 affects Flowise before 3.1.0. The Faiss and SimpleStore vector store implementations accept unsanitized basePath parameters from authenticated users, a path traversal flaw (CWE-22). An attacker with a valid API token can write vector store data to arbitrary filesystem locations, which the source says could enable code execution or data exfiltration.
Fix: Fixed in 3.1.0. Upgrade Flowise to version 3.1.0 or later.
NVD/CVE DatabaseBias Amplification in RAG: Poisoning Knowledge Retrieval to Steer LLMs
Jul 2, 2026LowResearchPeer-reviewedSecurityResearchResearchers show that poisoning a retrieval-augmented generation (RAG) system can amplify bias in an LLM's outputs, even for gender-neutral queries. Their Bias Retrieval and Reward Attack (BRRA) framework generates adversarial documents using multi-objective reward functions, manipulates retrieval with subspace projection, and uses a cyclic feedback mechanism, with experiments on several mainstream models showing significant bias increases. The paper also explores a dual-stage defense mechanism to mitigate the attack.
Fix: The source mentions a dual-stage defense mechanism that it says can effectively mitigate the impacts of the attack, but it does not describe its specifics, configuration or implementation.
IEEE Xplore (Security & AI Journals)External Data Extraction Attacks Against Retrieval-Augmented Large Language Models
Jun 18, 2026InfoResearchPeer-reviewedSecurityResearchThis paper formalizes external data extraction attacks (EDEAs) against retrieval-augmented LLMs (RA-LLMs), where sensitive or copyrighted knowledge-base data can be extracted verbatim. The authors propose a framework built from extraction instruction, jailbreak operator, and retrieval trigger, and implement an attack called Secret. Across 4 models, including 3 commercial LLMs, Secret outperforms prior attacks and succeeds against all 16 tested RAG instances, extracting 35% of the data from RAG powered by Claude 3.7 Sonnet where other attacks yield 0%.
IEEE Xplore (Security & AI Journals)Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language Models
Jun 2, 2026InfoResearchPeer-reviewedSecurityResearchResearchers present the first backdoor attacks against graph-based Retrieval-Augmented Generation (RAG) systems used with LLMs. The attacker poisons a crafted corpus in the external database so that trigger entities are inserted into the knowledge graph, causing the model to give attacker-chosen answers only for trigger-containing queries while answering other queries correctly. The authors evaluate three trigger types (word-level, topic-level and semantic-level) with increasing stealth across multiple knowledge databases and language models, and warn of risks to chatbots and agents built on such systems.
IEEE Xplore (Security & AI Journals)CVE-2026-45312: RAGFlow template injection in prompt generator allows OS command execution
May 29, 2026CriticalVulnerabilitySecurityCVE-2026-45312CVE-2026-45312 affects RAGFlow, an open-source RAG engine, in version 0.24.0 and earlier. A Jinja2 template injection in the prompt generator (rag/prompts/generator.py) lets any authenticated user execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the flaw. The weakness is classified as CWE-1336.
NVD/CVE DatabaseParaVul: A Parallel Large Language Model and Retrieval-Augmented Framework for Smart Contract Vulnerability Detection
May 18, 2026InfoResearchPeer-reviewedResearchSecurityParaVul is a framework that combines parallel LLM fine-tuning with retrieval-augmented generation to detect smart contract vulnerabilities more accurately than static analysis and formal verification. It introduces Sparse Low-Rank Adaptation (SLoRA), which inserts parallel sparse and low-rank branches after the attention projection and feed-forward block, and a hybrid RAG system combining Okapi BM25 with dense retrieval. Simulation results report F1 scores of 0.9398 for single-label and 0.9930 for multi-label detection.
IEEE Xplore (Security & AI Journals)GHSA-65pg-qhhw-mxwg: Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
May 14, 2026MediumVulnerabilitySecurityCVE-2026-45397GHSA-65pg-qhhw-mxwg affects Open WebUI's `main` branch, confirmed unpatched through v0.9.2. The `get_status()` handler in `backend/open_webui/routers/retrieval.py`, served at `GET /api/v1/retrieval/`, lacks an authentication dependency, so any unauthenticated client can read live RAG configuration. The disclosed fields include the RAG template, embedding engine and model, reranking model, and chunk size and overlap. The advisory rates it Medium, with a CVSSv3.1 score of 5.3.
Fix: Add the `get_verified_user` dependency to `get_status()` (or `get_admin_user` for stricter control), for example `async def get_status(request: Request, user=Depends(get_verified_user)):`.
GitHub Advisory DatabaseGHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks
May 14, 2026HighVulnerabilitySecurityFlowiseAI's OpenAI Assistants vector store routes at packages/server/src/routes/openai-assistants-vector-store/index.ts have no checkAnyPermission() middleware on any CRUD operation. Any authenticated user, regardless of role, can create, update, or delete vector stores, upload files to them, and delete files. The source rates the issue HIGH (CVSS ~8.1) under CWE-306 and says the impact includes uploading malicious files and exfiltrating stored documents.
GitHub Advisory DatabaseCVE-2026-42463: SQLBot cross-workspace authorization bypass in export and upload endpoints
May 13, 2026HighVulnerabilitySecurityCVE-2026-42463CVE-2026-42463 affects SQLBot versions prior to 1.8.0, a Text-to-SQL system built on large language models and RAG. The /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints contain a Cross-Workspace IDOR and authorization bypass (CWE-639), letting an attacker access and modify database schemas and data sources belonging to other tenants or workspaces. GitHub rates it CVSS 4.0 8.6 (HIGH); NVD has not yet provided an assessment.
Fix: Fixed in 1.8.0.
NVD/CVE DatabaseCVE-2026-33324: SQLBot prompt injection in Text2SQL chat interface leading to SQL execution
May 5, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-33324SQLBot, a Text-to-SQL system built on large language models and RAG, is affected in versions 1.7.0 and earlier. Its Text2SQL chat interface concatenates the user-provided question directly into the LLM prompt without filtering, and executes the SQL extracted from the LLM response without validation. An authenticated attacker can craft a malicious question to make the LLM generate and run arbitrary SQL, which, when connected to a PostgreSQL data source, can lead to remote code execution via COPY FROM PROGRAM.
Fix: Fixed in 1.7.1.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.