CVE-2025-25282 | infiniflow ragflow up to 0.13.0 //user/list authorization (GHSA-wc5v-g79p-7hch)
A vulnerability was found in infiniflow ragflow up to 0.13.0 and classified as critical. This issue affects some unknown processing of the file //user/list. The manipulation leads to authorization bypass.
The identification of this vulnerability is CVE-2025-25282. The attack may be initiated remotely. There is no exploit available.