CVE-2025-69286 | infiniflow ragflow up to 0.21.x Personal API generation of predictable numbers or identifiers (GHSA-9j5g-g4xm-57w7 / EUVD-2025-206092)
A vulnerability has been found in infiniflow ragflow up to 0.21.x and classified as problematic. Affected by this issue is some unknown functionality of the component Personal API. This manipulation causes generation of predictable numbers or identifiers.
This vulnerability is tracked as CVE-2025-69286. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.