submitted by /u/pipewire
[link] [comments]
Normal view
Received β 14 April 2026
β
/r/netsec - Information Security News & Discussion
-
/r/netsec - Information Security News & Discussion
- Common Entra ID Security Assessment Findings β Part 4: Weak Conditional Access Policies
Codex Hacked a Samsung TV
14 April 2026 at 03:09
-
/r/netsec - Information Security News & Discussion
- Unpatched RAGFlow Vulnerability Allows Post-Auth RCE
Unpatched RAGFlow Vulnerability Allows Post-Auth RCE
13 April 2026 at 16:57
The current version of RAGFlow, a widely-deployed Retrieval Augmented Generation solution, contains a post-auth vulnerability that allows for arbitrary code execution.
This post includes a POC, walkthrough and patch.
The TL;DR is to make sure your RAGFlow instances aren't on the public internet, that you have the minimum number of necessary users, and that those user accounts are protected by complex passwords. (This is especially true if you're using Infinity for storage.)
[link] [comments]