CVE-2025-68700 | infiniflow ragflow up to 0.22.x Frontend Canvas CodeExec eval os command injection
A vulnerability classified as critical has been found in infiniflow ragflow up to 0.22.x. This affects the function eval of the component Frontend Canvas CodeExec Component. Performing a manipulation results in os command injection.
This vulnerability was named CVE-2025-68700. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.