Retrieval-augmented generation
Systems that feed retrieved documents or vector-search results into a model's context.
- All items
- 33
- Last 90 days
- 10
- Change
- -9%vs 11 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 1 |
| Dec 2025 | 0 |
| Jan 2026 | 1 |
| Feb 2026 | 3 |
| Mar 2026 | 4 |
| Apr 2026 | 2 |
| May 2026 | 6 |
| Jun 2026 | 2 |
| Jul 2026 | 2 |
| Aug 2026 | 1 |
| Sep 2026 | 8 |
| Oct 2026 | 1 |
33 items
Securing RAG pipelines in enterprise SaaS
Apr 28, 2026InfoNewsSecurityResearchThe article argues that Retrieval-Augmented Generation (RAG) gives AI agents in enterprise SaaS real-time access to sensitive company data, which creates serious security liabilities. It cites recent incidents, including the "EchoLeak" zero-click exfiltration from Microsoft 365 Copilot's RAG pipeline in late 2025 and vector database exposures in 2024 to 2025. It then outlines a three-phase RAG pipeline (ingestion and embedding, storage and retrieval, generation and orchestration) and maps threats to each phase.
CSO OnlineCVE-2026-35486: text-generation-webui SSRF in superbooga RAG extensions via user-supplied URLs
Apr 7, 2026HighVulnerabilitySecurityCVE-2026-35486CVE-2026-35486 affects text-generation-webui before 4.3, specifically the superbooga and superboogav2 RAG extensions. These extensions fetch user-supplied URLs with requests.get() and perform no scheme check, IP filtering, or hostname allowlisting. An attacker can reach cloud metadata endpoints, steal IAM credentials, probe internal services, and exfiltrate the fetched content through the RAG pipeline.
Fix: Fixed in 4.3.
NVD/CVE DatabaseCVE-2026-32950: SQLBot SQL injection via uploadExcel endpoint enables remote code execution
Mar 20, 2026CriticalVulnerabilitySecurityCVE-2026-32950SQLBot, an LLM and RAG-based data query system, contains a SQL injection flaw in the /api/v1/datasource/uploadExcel endpoint in versions prior to 1.7.0. Excel sheet names are concatenated into PostgreSQL table names and embedded in COPY statements via f-strings, so any authenticated user, even the lowest-privileged, can reach remote code execution through a two-stage upload that bypasses the 31-character sheet name limit. Confirmed impacts include command execution as the postgres user, exfiltration of files such as /etc/passwd and /etc/shadow, and full database takeover.
Fix: Fixed in 1.7.0.
NVD/CVE DatabaseCVE-2026-32949: SQLBot server-side request forgery via datasource check endpoint
Mar 20, 2026HighVulnerabilitySecurityCVE-2026-32949SQLBot, an LLM and RAG-based data query system, has an SSRF vulnerability in versions prior to 1.7.0. An attacker can abuse the /api/v1/datasource/check endpoint with a forged MySQL data source using extraJdbc="local_infile=1", so the backend connects to an attacker-controlled rogue MySQL server that issues a LOAD DATA LOCAL INFILE command during the handshake. This makes the target read arbitrary local files, such as /etc/passwd or configuration files, and send their contents back to the attacker.
Fix: This issue was fixed in version 1.7.0.
NVD/CVE DatabaseCVE-2026-32622: SQLBot stored prompt injection via Excel upload enables code execution
Mar 19, 2026CriticalVulnerabilitySecurityCVE-2026-32622SQLBot, an LLM and RAG-based data query system, contains a stored prompt injection vulnerability in versions 1.5.0 and below. A missing permission check on the Excel upload API lets any authenticated user upload terminology with unsanitized payloads, which is injected into the LLM's system prompt without semantic fencing. An attacker can thereby steer the model into generating malicious PostgreSQL commands such as COPY ... TO PROGRAM, achieving remote code execution with postgres user privileges on the database or application server.
Fix: Fixed in v1.6.0.
NVD/CVE DatabaseEfficient Vector-Multiplicative Privacy-Preserving Retrieval-Augmented Generation for Large Language Models
Mar 3, 2026InfoResearchPeer-reviewedResearchPrivacyCipheRAG is a privacy-preserving retrieval-augmented generation framework for large language models that aims to balance knowledge confidentiality with retrieval efficiency. It combines a searchable inner product functional encryption mechanism, enhanced with asymmetric locality-sensitive hashing, with a decryption-enabled attention mechanism that feeds decrypted knowledge into the generation process. The authors report up to 35x faster generation and 15x faster QKV computation than FHE- and OT-based baselines.
IEEE Xplore (Security & AI Journals)Why 2025’s agentic AI boom is a CISO’s worst nightmare
Feb 17, 2026InfoNewsSecurityResearchAn opinion-style article argues that by late 2025 enterprise AI had shifted from chat-based LLMs to autonomous agents, driven by the failure of standard RAG systems. It states that 72% to 80% of enterprise RAG implementations underperform or fail within their first year, and that agentic RAG introduces a new risk: autonomous execution of malicious instructions. The source text is cut off before its security analysis.
CSO OnlineCVE-2026-26190: Milvus authentication bypass through debug and REST API endpoints on port 9091
Feb 13, 2026CriticalVulnerabilitySecurityCVE-2026-26190Milvus versions prior to 2.5.27 and 2.6.10 expose TCP port 9091 by default, enabling authentication bypasses. The /expr debug endpoint uses a weak, predictable default token derived from etcd.rootPath (default: by-dev), allowing arbitrary expression evaluation. The full REST API (/api/v1/*) is registered on the metrics/management port without authentication, giving unauthenticated access to all business operations, including data manipulation and credential management.
Fix: Fixed in 2.5.27 and 2.6.10.
NVD/CVE DatabaseCVE-2026-25628: Qdrant arbitrary file append via /logger endpoint
Feb 6, 2026HighVulnerabilitySecurityCVE-2026-25628CVE-2026-25628 affects Qdrant, a vector similarity search engine and vector database, in versions from 1.9.3 up to but not including 1.16.0. An attacker with read-only access can append to arbitrary files through the /logger endpoint by supplying a controlled on_disk.log_file path. The weakness is classified as CWE-73, External Control of File Name or Path.
Fix: Fixed in 1.16.0.
NVD/CVE DatabaseCVE-2025-69285: SQLBot missing authentication on Excel upload endpoint allows database injection
Jan 21, 2026MediumVulnerabilitySecurityCVE-2025-69285SQLBot, an LLM and RAG-based data query system, contains a missing authentication flaw in versions prior to 1.5.0. The /api/v1/datasource/uploadExcel endpoint is on the authentication whitelist, so TokenMiddleware skips token validation, letting a remote unauthenticated attacker upload arbitrary Excel/CSV files. Uploaded files are parsed by pandas and written to the PostgreSQL database via to_sql() with if_exists='replace', allowing direct data injection.
Fix: Fixed in v1.5.0. No known workarounds are available.
NVD/CVE DatabaseCVE-2025-64513: Milvus authentication bypass in Proxy component grants administrative access
Nov 10, 2025CriticalVulnerabilitySecurityCVE-2025-64513Milvus versions prior to 2.4.24, 2.5.21, and 2.6.5 contain a flaw that lets an unauthenticated attacker bypass all authentication in the Milvus Proxy component. A successful attacker gains full administrative access to the Milvus cluster, with the ability to read, modify, or delete data and perform privileged operations such as database or collection management.
Fix: Fixed in Milvus 2.4.24, 2.5.21, and 2.6.5. If immediate upgrade is not possible, remove the sourceID header from all incoming requests at the gateway, API gateway, or load balancer level before they reach the Milvus Proxy.
NVD/CVE DatabaseCVE-2025-21604: LangChain4j-AIDeepin file upload conflicts from MD5 file hashing
Jan 6, 2025MediumVulnerabilitySecurityCVE-2025-21604CVE-2025-21604 affects LangChain4j-AIDeepin, a retrieval augmented generation (RAG) project, in versions prior to 3.5.0. The project hashes uploaded files with MD5, a weak hash under CWE-328, which may cause file upload conflicts. GitHub, Inc. is the CNA, rating it CVSS 4.0 6.9 MEDIUM.
Fix: Fixed in 3.5.0.
NVD/CVE DatabaseCVE-2024-56137: MaxKB remote command execution in function library custom scripts
Jan 2, 2025MediumVulnerabilitySecurityCVE-2024-56137CVE-2024-56137 affects MaxKB, an open source knowledge base question-answering system built on a large language model and retrieval-augmented generation (RAG). Versions prior to 1.9.0 contain a remote command execution flaw in the function library module that lets privileged users run OS commands through custom scripts. The vulnerability is tracked as CWE-78 and was reported by GitHub, Inc.
Fix: Fixed in v1.9.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.