GHSA-v2xr-wvrv-p969 · Severity: high · Ecosystem: pip — RAGAS has an Arbitrary File Read vulnerability
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
Conclusion & alert: CVE-2025-45691 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.03%). Core evidence: 3 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-21 | 0.05% | 0.03% | -0.03% |
| 2 | 2026-03-06 | — | 0.05% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-v2xr-wvrv-p969 · Severity: high · Ecosystem: pip — RAGAS has an Arbitrary File Read vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-45691 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| vibrantlabsai | ragas | >= 0.2.3, <= 0.2.14 | cpe:2.3:a:vibrantlabsai:ragas:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerability | Exploit Third Party Advisory |
| https://github.com/explodinggradients/ragas/blob/e97886ac976465efb60e5949c5d69baf30cc811d/src/ragas/prompt/multi_modal_prompt.py#L202 | Product |
| https://github.com/explodinggradients/ragas/pull/1559 | Exploit Issue Tracking Patch |
| https://github.com/vibrantlabsai/ragas/pull/1991 | Exploit Issue Tracking Patch Vendor Advisory |