Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95ww-475f-pr4f

Опубликовано: 20 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.1
CVSS3: 6.3

Описание

RAGAS has SSRF via Multi-Modal Faithfulness Collections Module

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The security patch for CVE-2025-45691 was applied to a different module only. The vendor was contacted early about this disclosure but did not respond in any way.

Пакеты

Наименование

ragas

pip
Затронутые версииВерсия исправления

>= 0.2.3, <= 0.4.3

Отсутствует

EPSS

Процентиль: 20%
0.00277
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.1
redhat
3 месяца назад

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The security patch for CVE-2025-45691 was applied to a different module only. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS3: 6.3
nvd
3 месяца назад

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The security patch for CVE-2025-45691 was applied to a different module only. The vendor was contacted early about this disclosure but did not respond in any way.

EPSS

Процентиль: 20%
0.00277
Низкий

2.1 Low

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-918