Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery
Vulnerability Description
A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The security patch for CVE-2025-45691 was applied to a different module only. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
服务端请求伪造(SSRF)
Vulnerability Title
ragas 安全漏洞
Vulnerability Description
ragas是Vibrant Labs开源的一个优化和评估大语言模型的工具包。 ragas 0.4.3及之前版本存在安全漏洞,该漏洞源于对文件src/ragas/metrics/collections/multi_modal_faithfulness/util.py中_try_process_local_file/_try_process_url函数的参数retrieved_contexts操作不当,可能导致服务端请求伪造。
CVSS Information
N/A
Vulnerability Type
N/A