CVE-2025-45691: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-45691 is an Arbitrary File Read (Local File Inclusion) vulnerability in the ImageTextPromptValue class within Exploding Gradients RAGAS, an open-source RAG evaluation framework. It affects versions v0.2.3 through v0.2.14 and stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs. The vulnerability was published on March 5, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (Feedly, GitHub Fix PR).

Technical details

The root cause is classified as CWE-22 (Path Traversal / Improper Limitation of a Pathname to a Restricted Directory). The vulnerable code resides in src/ragas/prompt/multi_modal_prompt.py within the ImageTextPromptValue class. The is_valid_url() method only checked for the presence of a URL scheme and netloc, allowing file:// URIs (e.g., file://localhost/etc/passwd#fake.jpg) to pass validation; mimetypes.guess_type() could be tricked by appending an image extension in a URL fragment, which urllib.request.urlopen ignores when accessing the filesystem. Additionally, the encode_image_to_base64() method called open() directly on attacker-controlled input, and the download_and_encode_image() method used urllib.request.urlopen without restricting schemes, enabling both LFI and SSRF (GitHub Fix PR, Vulnerable Source).

Impact

Successful exploitation allows an unauthenticated remote attacker to read arbitrary files accessible to the application process (e.g., /etc/passwd, application secrets, credentials, private keys), resulting in high confidentiality impact with no integrity or availability impact. Beyond LFI, the same code path enables Server-Side Request Forgery (SSRF), allowing attackers to probe internal network services or cloud metadata endpoints (e.g., AWS 169.254.169.254), facilitating lateral movement or credential theft in cloud-hosted deployments. Reading large files such as /dev/zero via the file:// scheme could also cause Denial of Service through memory exhaustion (GitHub Fix PR).

Exploitability

A public technical write-up and proof-of-concept details are available at https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerability, referenced in the NVD entry. The vulnerability requires no authentication and no user interaction, making it exploitable by any network-accessible attacker who can supply a crafted retrieved_contexts value to a RAGAS evaluation pipeline. The EPSS score is approximately 0.053% (low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or active in-the-wild exploitation campaigns have been reported (Feedly).

Exploitation steps

  1. Identify target: Locate a deployment of RAGAS v0.2.3–v0.2.14 that accepts user-controlled multimodal evaluation inputs (e.g., a web service or API wrapping RAGAS evaluation with MultiModalFaithfulness or MultiModalRelevance metrics).
  2. Craft malicious payload: Construct a dataset entry where the retrieved_contexts field contains a file:// URI with an image extension appended as a URL fragment to bypass MIME type detection, e.g., file://localhost/etc/passwd#fake.jpg.
  3. Submit to evaluation pipeline: Pass the crafted dataset to the RAGAS evaluate() function. The ImageTextPromptValue.to_messages() method processes each context item, calling is_image() which uses mimetypes.guess_type() on the fragment-manipulated URL, returning an image MIME type.
  4. Trigger file read: The get_image() method calls download_and_encode_image() with urllib.request.urlopen(url), which resolves the file:// URI and reads the target file from the local filesystem, ignoring the #fake.jpg fragment.
  5. Exfiltrate data: The file contents are base64-encoded and embedded in the prompt sent to the LLM, potentially appearing in evaluation outputs, logs, or API responses accessible to the attacker (GitHub Fix PR, Vulnerable Source).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the RAGAS application server to internal IP ranges (e.g., 169.254.169.254, 10.x.x.x, 192.168.x.x) or unexpected external hosts, indicating SSRF exploitation attempts.
  • Logs: Application or LLM API logs containing base64-encoded strings that decode to plaintext system files (e.g., /etc/passwd content, SSH keys); error traces from urllib.request.urlopen involving file:// URIs.
  • File System: No direct file artifacts are created by exploitation, but audit logs may show unexpected file access by the Python process to sensitive paths (e.g., /etc/passwd, /etc/shadow, ~/.ssh/id_rsa, application config files).
  • Process: Unusual network connections initiated by the Python interpreter process running RAGAS to internal metadata services or unexpected external endpoints.

Mitigation and workarounds

The fix was merged into the vibrantlabsai/ragas main branch on May 5, 2025 (PR #1991). Users should upgrade to a version of RAGAS released after this date that includes the patched multi_modal_prompt.py. The remediation replaces the insecure is_image/is_valid_url logic with an explicit allowlist of URL schemes (http, https only; file:// blocked by default), mandatory content validation using the Pillow library, download size limits, and strict path confinement for local files (disabled by default). As a workaround for those unable to upgrade immediately, avoid passing user-controlled or untrusted strings in the retrieved_contexts parameter of multimodal evaluation datasets, and restrict network egress from RAGAS application servers (GitHub Fix PR).

Community reactions

The vulnerability was discovered and reported by security researcher Adithyan AK, who also authored the fix (PR #1991) and published a technical write-up at adithyanak.com. The RAGAS maintainer (jjmachan) acknowledged the report promptly and merged the fix. The vulnerability was noted on Mastodon by @thehackerwire and picked up by automated CVE tracking feeds including VulDB and ENISA EUVD. No major media coverage or broad community controversy has been observed (GitHub Fix PR).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management