CVE-2025-45691
Last modified
CVE-2025-45691 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vibrantlabsai | Ragas | >= 0.2.3, <= 0.2.14 |
References
- https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerabilityExploit, Third Party Advisory
- https://github.com/explodinggradients/ragas/pull/1559Exploit, Issue Tracking, Patch
- https://github.com/vibrantlabsai/ragas/pull/1991Exploit, Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-45691?
How severe is CVE-2025-45691?
How do I fix CVE-2025-45691?
Are you affected by CVE-2025-45691?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
