CVE-2026-51895 | Infiniflow Ragflow up to 0.24.0 api/apps/kb_app.py update_metadata_setting access control
A vulnerability marked as critical has been reported in Infiniflow Ragflow up to 0.24.0. This affects the function update_metadata_setting of the file api/apps/kb_app.py. This manipulation causes improper access controls.
This vulnerability appears as CVE-2026-51895. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More