Retrieval-augmented generation
Systems that feed retrieved documents or vector-search results into a model's context.
- All items
- 33
- Last 90 days
- 10
- Change
- -9%vs 11 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 1 |
| Dec 2025 | 0 |
| Jan 2026 | 1 |
| Feb 2026 | 3 |
| Mar 2026 | 4 |
| Apr 2026 | 2 |
| May 2026 | 6 |
| Jun 2026 | 2 |
| Jul 2026 | 2 |
| Aug 2026 | 1 |
| Sep 2026 | 8 |
| Oct 2026 | 1 |
22 items
CVE-2026-18875: IBM FTM for RedHat OpenShift RAG poisoning via unauthenticated upsert
Sep 23, 2026HighVulnerabilitySecurityCVE-2026-18875IBM Financial Transaction Manager (FTM) for RedHat OpenShift is affected by CVE-2026-18875, a RAG poisoning flaw (CWE-74) caused by an unauthenticated runbook upsert in the FTM AI agent server at api.vectordb.runbooks.js:51. An unauthenticated attacker can insert malicious runbook content into the agent's vector database. This can steer AI-driven MCP tool calls, potentially triggering unauthorized payment actions or exfiltrating payment data.
NVD/CVE DatabaseCVE-2026-85709: LightRAG API server leaks raw Python exception text in error responses
Sep 22, 2026MediumVulnerabilitySecurityCVE-2026-85709LightRAG's API server, before version 1.5.5, returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py and lightrag_server.py. A network client that triggers an error can read server filesystem paths, database host, port, user and database names, language-model provider diagnostics, configuration details and library internals, and with URI-configured backends possibly connection strings containing credentials. The default unauthenticated configuration makes these responses reachable without credentials.
Fix: Fixed in 1.5.5.
NVD/CVE DatabaseCVE-2026-53557: SQLBot second-order SQL injection through Excel datasource tableName
Sep 17, 2026CriticalVulnerabilitySecurityCVE-2026-53557SQLBot, a Text-to-SQL system built on large language models and RAG, is affected prior to version 1.9.0. An authenticated user can submit a crafted sheet["tableName"] value through POST /api/v1/datasource/, which is stored without safe identifier handling. When the datasource is later removed via DELETE /api/v1/datasource/{id}, PostgreSQL executes the stored value in cleanup SQL, allowing COPY TO PROGRAM and arbitrary operating-system commands under the postgres process privileges inside the SQLBot container.
Fix: Fixed in version 1.9.0.
NVD/CVE DatabaseCVE-2026-53556: SQLBot SQL injection in previewData endpoint table_name exposes server files
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-53556SQLBot, a Text-to-SQL system built on large language models and RAG, is affected by CVE-2026-53556 before version 1.9.0. The POST /api/v1/datasource/previewData endpoint places the client-controlled table_name value into generated SQL without safe identifier handling. An authenticated user can use a crafted table_name to call pg_read_file(), pg_read_binary_file() or pg_ls_dir() through a datasource pointed at the internal PostgreSQL service, reading filesystem content such as /etc/hosts and /etc/passwd, and potentially configuration, credentials and source code. In the default tested trusted loopback authentication configuration, the connection runs with PostgreSQL superuser privileges.
Fix: This issue is fixed in version 1.9.0.
NVD/CVE DatabaseCVE-2026-53555: SQLBot stored cross-site scripting through uploaded SVG assistant logo
Sep 17, 2026MediumVulnerabilitySecurityCVE-2026-53555SQLBot, a Text-to-SQL system built on large language models and RAG, stores uploaded image/svg+xml assistant UI logos without sanitizing embedded active content before version 1.9.0. An authenticated uploader can submit such a file through PATCH /api/v1/system/assistant/ui, and SQLBot serves it inline from the same origin via GET /api/v1/system/assistant/picture/{filename}. When another user loads the file, embedded JavaScript runs in the SQLBot web application context with access to the victim's session data and actions.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-53554: SQLBot arbitrary code execution through parseExcel upload endpoint
Sep 17, 2026HighVulnerabilitySecurityCVE-2026-53554CVE-2026-53554 affects SQLBot, a Text-to-SQL system built on large language models and RAG, prior to 1.9.0. The POST /api/v1/datasource/parseExcel endpoint trusts attacker-controlled multipart filenames when choosing storage, and it writes uploaded content before spreadsheet parsing and validation finish. A crafted upload can plant a Python file in /opt/sqlbot/app/alembic/versions/ even when parsing fails and the endpoint returns an error. On the next startup or migration, Alembic imports that file and runs its module-level statements inside the SQLBot runtime.
Fix: Fixed in 1.9.0.
NVD/CVE DatabaseCVE-2026-56273: Flowise path traversal in Faiss and SimpleStore vector store basePath parameter
Jul 8, 2026MediumVulnerabilitySecurityCVE-2026-56273CVE-2026-56273 affects Flowise before 3.1.0. The Faiss and SimpleStore vector store implementations accept unsanitized basePath parameters from authenticated users, a path traversal flaw (CWE-22). An attacker with a valid API token can write vector store data to arbitrary filesystem locations, which the source says could enable code execution or data exfiltration.
Fix: Fixed in 3.1.0. Upgrade Flowise to version 3.1.0 or later.
NVD/CVE DatabaseCVE-2026-45312: RAGFlow template injection in prompt generator allows OS command execution
May 29, 2026CriticalVulnerabilitySecurityCVE-2026-45312CVE-2026-45312 affects RAGFlow, an open-source RAG engine, in version 0.24.0 and earlier. A Jinja2 template injection in the prompt generator (rag/prompts/generator.py) lets any authenticated user execute arbitrary OS commands on the server. Any normal user can register, create a Canvas workflow with a DuckDuckGo + LLM component chain, and trigger the flaw. The weakness is classified as CWE-1336.
NVD/CVE DatabaseGHSA-65pg-qhhw-mxwg: Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
May 14, 2026MediumVulnerabilitySecurityCVE-2026-45397GHSA-65pg-qhhw-mxwg affects Open WebUI's `main` branch, confirmed unpatched through v0.9.2. The `get_status()` handler in `backend/open_webui/routers/retrieval.py`, served at `GET /api/v1/retrieval/`, lacks an authentication dependency, so any unauthenticated client can read live RAG configuration. The disclosed fields include the RAG template, embedding engine and model, reranking model, and chunk size and overlap. The advisory rates it Medium, with a CVSSv3.1 score of 5.3.
Fix: Add the `get_verified_user` dependency to `get_status()` (or `get_admin_user` for stricter control), for example `async def get_status(request: Request, user=Depends(get_verified_user)):`.
GitHub Advisory DatabaseGHSA-hmg2-jjjx-jcp2: FlowiseAI: Vector Store No Permission Checks
May 14, 2026HighVulnerabilitySecurityFlowiseAI's OpenAI Assistants vector store routes at packages/server/src/routes/openai-assistants-vector-store/index.ts have no checkAnyPermission() middleware on any CRUD operation. Any authenticated user, regardless of role, can create, update, or delete vector stores, upload files to them, and delete files. The source rates the issue HIGH (CVSS ~8.1) under CWE-306 and says the impact includes uploading malicious files and exfiltrating stored documents.
GitHub Advisory DatabaseCVE-2026-42463: SQLBot cross-workspace authorization bypass in export and upload endpoints
May 13, 2026HighVulnerabilitySecurityCVE-2026-42463CVE-2026-42463 affects SQLBot versions prior to 1.8.0, a Text-to-SQL system built on large language models and RAG. The /api/v1/datasource/exportDsSchema and /api/v1/datasource/uploadDsSchema endpoints contain a Cross-Workspace IDOR and authorization bypass (CWE-639), letting an attacker access and modify database schemas and data sources belonging to other tenants or workspaces. GitHub rates it CVSS 4.0 8.6 (HIGH); NVD has not yet provided an assessment.
Fix: Fixed in 1.8.0.
NVD/CVE DatabaseCVE-2026-33324: SQLBot prompt injection in Text2SQL chat interface leading to SQL execution
May 5, 2026CriticalVulnerabilitySecurityIndustryCVE-2026-33324SQLBot, a Text-to-SQL system built on large language models and RAG, is affected in versions 1.7.0 and earlier. Its Text2SQL chat interface concatenates the user-provided question directly into the LLM prompt without filtering, and executes the SQL extracted from the LLM response without validation. An authenticated attacker can craft a malicious question to make the LLM generate and run arbitrary SQL, which, when connected to a PostgreSQL data source, can lead to remote code execution via COPY FROM PROGRAM.
Fix: Fixed in 1.7.1.
NVD/CVE DatabaseCVE-2026-35486: text-generation-webui SSRF in superbooga RAG extensions via user-supplied URLs
Apr 7, 2026HighVulnerabilitySecurityCVE-2026-35486CVE-2026-35486 affects text-generation-webui before 4.3, specifically the superbooga and superboogav2 RAG extensions. These extensions fetch user-supplied URLs with requests.get() and perform no scheme check, IP filtering, or hostname allowlisting. An attacker can reach cloud metadata endpoints, steal IAM credentials, probe internal services, and exfiltrate the fetched content through the RAG pipeline.
Fix: Fixed in 4.3.
NVD/CVE DatabaseCVE-2026-32950: SQLBot SQL injection via uploadExcel endpoint enables remote code execution
Mar 20, 2026CriticalVulnerabilitySecurityCVE-2026-32950SQLBot, an LLM and RAG-based data query system, contains a SQL injection flaw in the /api/v1/datasource/uploadExcel endpoint in versions prior to 1.7.0. Excel sheet names are concatenated into PostgreSQL table names and embedded in COPY statements via f-strings, so any authenticated user, even the lowest-privileged, can reach remote code execution through a two-stage upload that bypasses the 31-character sheet name limit. Confirmed impacts include command execution as the postgres user, exfiltration of files such as /etc/passwd and /etc/shadow, and full database takeover.
Fix: Fixed in 1.7.0.
NVD/CVE DatabaseCVE-2026-32949: SQLBot server-side request forgery via datasource check endpoint
Mar 20, 2026HighVulnerabilitySecurityCVE-2026-32949SQLBot, an LLM and RAG-based data query system, has an SSRF vulnerability in versions prior to 1.7.0. An attacker can abuse the /api/v1/datasource/check endpoint with a forged MySQL data source using extraJdbc="local_infile=1", so the backend connects to an attacker-controlled rogue MySQL server that issues a LOAD DATA LOCAL INFILE command during the handshake. This makes the target read arbitrary local files, such as /etc/passwd or configuration files, and send their contents back to the attacker.
Fix: This issue was fixed in version 1.7.0.
NVD/CVE DatabaseCVE-2026-32622: SQLBot stored prompt injection via Excel upload enables code execution
Mar 19, 2026CriticalVulnerabilitySecurityCVE-2026-32622SQLBot, an LLM and RAG-based data query system, contains a stored prompt injection vulnerability in versions 1.5.0 and below. A missing permission check on the Excel upload API lets any authenticated user upload terminology with unsanitized payloads, which is injected into the LLM's system prompt without semantic fencing. An attacker can thereby steer the model into generating malicious PostgreSQL commands such as COPY ... TO PROGRAM, achieving remote code execution with postgres user privileges on the database or application server.
Fix: Fixed in v1.6.0.
NVD/CVE DatabaseCVE-2026-26190: Milvus authentication bypass through debug and REST API endpoints on port 9091
Feb 13, 2026CriticalVulnerabilitySecurityCVE-2026-26190Milvus versions prior to 2.5.27 and 2.6.10 expose TCP port 9091 by default, enabling authentication bypasses. The /expr debug endpoint uses a weak, predictable default token derived from etcd.rootPath (default: by-dev), allowing arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without authentication, giving unauthenticated access to all business operations, including data manipulation and credential management.
Fix: Fixed in 2.5.27 and 2.6.10.
NVD/CVE DatabaseCVE-2026-25628: Qdrant arbitrary file append via /logger endpoint
Feb 6, 2026HighVulnerabilitySecurityCVE-2026-25628CVE-2026-25628 affects Qdrant, a vector similarity search engine and vector database, in versions from 1.9.3 up to but not including 1.16.0. An attacker with read-only access can append to arbitrary files through the /logger endpoint by supplying a controlled on_disk.log_file path. The weakness is classified as CWE-73, External Control of File Name or Path.
Fix: Fixed in 1.16.0.
NVD/CVE DatabaseCVE-2025-69285: SQLBot missing authentication on Excel upload endpoint allows database injection
Jan 21, 2026MediumVulnerabilitySecurityCVE-2025-69285SQLBot, an LLM and RAG-based data query system, contains a missing authentication flaw in versions prior to 1.5.0. The /api/v1/datasource/uploadExcel endpoint is on the authentication whitelist, so TokenMiddleware skips token validation, letting a remote unauthenticated attacker upload arbitrary Excel/CSV files. Uploaded files are parsed by pandas and written to the PostgreSQL database via to_sql() with if_exists='replace', allowing direct data injection.
Fix: Fixed in v1.5.0. No known workarounds are available.
NVD/CVE DatabaseCVE-2025-64513: Milvus authentication bypass in Proxy component grants administrative access
Nov 10, 2025CriticalVulnerabilitySecurityCVE-2025-64513Milvus versions prior to 2.4.24, 2.5.21, and 2.6.5 contain a flaw that lets an unauthenticated attacker bypass all authentication in the Milvus Proxy component. A successful attacker gains full administrative access to the Milvus cluster, with the ability to read, modify, or delete data and perform privileged operations such as database or collection management.
Fix: Fixed in Milvus 2.4.24, 2.5.21, and 2.6.5. If immediate upgrade is not possible, remove the sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they reach the Milvus Proxy.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.