Junglewise Threat Intelligence

CVE-2026-6587: vibrantlabsai RAGAS SSRF in Collections Module

CVE-2026-6587 · Severity: medium · CVSS 6.3 · Published 2026-04-20

Technologies: Red Hat OpenShift AI (RHOAI). Vendors: Red Hat, PyPI.

Executive brief

A security vulnerability exists in RAGAS, a framework used to evaluate Retrieval-Augmented Generation (RAG) systems. By providing specially crafted input, an attacker can force the server to read local files or access internal network services that are not intended to be public. This could lead to the theft of sensitive configuration files, cloud credentials, or internal data, potentially compromising the entire server infrastructure.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the vibrantlabsai RAGAS library up to version 0.4.3. The flaw is located in the _try_process_local_file and _try_process_url functions within src/ragas/metrics/collections/multi_modal_faithfulness/util.py. An attacker can manipulate the 'retrieved_contexts' argument to bypass image validation checks using URI schemes like 'file://' combined with URL fragments (e.g., #payload.jpg) to trick the mimetypes detection. This allows for arbitrary local file reads and internal network probing via urllib.request.urlopen. While a similar issue (CVE-2025-45691) was previously patched in a different module, this specific component remains vulnerable. No official patch from the vendor is currently confirmed.

Affected products

  • vibrantlabsai RAGAS up to 0.4.3
  • Red Hat OpenShift AI (RHOAI)

Timeline

  • 2026-04-20: disclosed: Initial public disclosure of the vulnerability.
  • 2026-04-20: advisory: NVD and Red Hat published advisories.

References

Related threats