Retrieval-augmented generation
Systems that feed retrieved documents or vector-search results into a model's context.
- All items
- 33
- Last 90 days
- 10
- Change
- -9%vs 11 before
Items per month
| Month | Items |
|---|---|
| May 2025 | 0 |
| Jun 2025 | 0 |
| Jul 2025 | 0 |
| Aug 2025 | 0 |
| Sep 2025 | 0 |
| Oct 2025 | 0 |
| Nov 2025 | 1 |
| Dec 2025 | 0 |
| Jan 2026 | 1 |
| Feb 2026 | 3 |
| Mar 2026 | 4 |
| Apr 2026 | 2 |
| May 2026 | 6 |
| Jun 2026 | 2 |
| Jul 2026 | 2 |
| Aug 2026 | 1 |
| Sep 2026 | 8 |
| Oct 2026 | 1 |
22 items
CVE-2025-21604: LangChain4j-AIDeepin file upload conflicts from MD5 file hashing
Jan 6, 2025MediumVulnerabilitySecurityCVE-2025-21604CVE-2025-21604 affects LangChain4j-AIDeepin, a retrieval augmented generation (RAG) project, in versions prior to 3.5.0. The project hashes uploaded files with MD5, a weak hash under CWE-328, which may cause file upload conflicts. GitHub, Inc. is the CNA, rating it CVSS 4.0 6.9 MEDIUM.
Fix: Fixed in 3.5.0.
NVD/CVE DatabaseCVE-2024-56137: MaxKB remote command execution in function library custom scripts
Jan 2, 2025MediumVulnerabilitySecurityCVE-2024-56137CVE-2024-56137 affects MaxKB, an open source knowledge base question-answering system built on a large language model and retrieval-augmented generation (RAG). Versions prior to 1.9.0 contain a remote command execution flaw in the function library module that lets privileged users run OS commands through custom scripts. The vulnerability is tracked as CWE-78 and was reported by GitHub, Inc.
Fix: Fixed in v1.9.0.
NVD/CVE Database
Topic added 2026-10-09. An item belongs to this topic when its title matches one of the topic's patterns or its summary mentions the topic at least twice. Report a wrong match with the feedback button on the item.