Skip to content
CVE-2025-51462: Ragflow XSS in Dialog Configuration

CVE-2025-51462: Ragflow XSS in Dialog Configuration

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.Artemiy Malyshau· Co-founder & CTO2 min read

Key takeaways

  • A stored cross-site scripting (XSS) was found in the dialog configuration functionality.
  • The vulnerability exists in the following function call chain:

Description#

A stored cross-site scripting (XSS) was found in the dialog configuration functionality. The application fails to properly sanitize user input in the prompt_config fields, particularly in the “Opening greeting” section under “Assistant Setting”. When this unsanitized content is later rendered using a markdown component with the rehype-raw plugin, malicious HTML and JavaScript can execute in victims’ browsers.

Source - Sink Analysis#

The vulnerability exists in the following function call chain:

  1. Source: set_dialog() in ragflow-0.17.2/api/apps/dialog_app.py
    • Accepts user-provided prompt_config parameter without sanitization: pythonCopy<code class=“hljs language-python”>prompt_config = req.get(<span class=“hljs-string”>“prompt_config”</span>, default_prompt) </code>
  2. Intermediate: DialogService.save() in ragflow-0.17.2/api/db/services/common_service.py
    • Stores unsanitized user input directly in the database: pythonCopy<code class=“hljs language-python”>sample_obj = cls.model(**kwargs).save(force_insert=<span class=“hljs-literal”>True</span>) </code>
  3. Intermediate: get_json_result() in ragflow-0.17.2/api/utils/api_utils.py
    • Returns unsanitized data in JSON response: pythonCopy<code class=“hljs language-python”>response = {<span class=“hljs-string”>“code”</span>: code, <span class=“hljs-string”>“message”</span>: message, <span class=“hljs-string”>“data”</span>: data} </code>
  4. Sink: HightLightMarkdown component in ragflow-0.17.2/web/src/components/highlight-markdown/index.tsx
    • Renders unsanitized content with rehype-raw plugin, allowing JavaScript execution: jsxCopy<code class=“hljs language-jsx”>rehypePlugins={[rehypeRaw, rehypeKatex]} </code>

Proof of Concept#

  1. Log into RAGFlow application
  2. Navigate to Chat section and click “Create an Assistant” button
  3. Locate the “Opening greeting” field (prompt_config.prologue) and enter the following payload:
<code class="hljs language-bash"><iframe srcdoc=<span class="hljs-string">"<script>alert('XSS Vulnerability in RAGFlow')</script>"</span>></iframe>
</code>
  1. Start a new conversation and observe that a JavaScript alert popup appears with the text “XSS Vulnerability in RAGFlow”

Impact#

Attackers can:

  • Execute arbitrary JavaScript in the context of other users’ browsers
  • Steal authentication tokens, session cookies, and other sensitive information
  • Perform unauthorized actions on behalf of the victim
  • Access sensitive data including knowledge base content

Fix: https://github.com/infiniflow/ragflow/pull/7669

Grayscale portrait of a young man looking left, wearing a striped lanyard, with an olive green dot pattern background.

Artemiy Malyshau

Co-founder & CTO

Artemiy served in an elite unit of the Austrian Cyber Forces, defending national infrastructure He was then the first employee at a government-backed cybersecurity research group, where he led security projects for Interpol and national governments. At Gecko he builds the platform trusted to sit inside Fortune 500 codebases, and holds it to the standard those governments taught him.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

Subscribe to the Gecko Security newsletter

Occasional updates, new content, and insights. No spam; unsubscribe anytime.

We use your email only to send you our newsletter. See our privacy policy for how we handle your data. You can unsubscribe at any time.