{"id":"PYSEC-2026-3047","summary":"RAGAS has an Arbitrary File Read vulnerability","details":"An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.","aliases":["CVE-2025-45691","GHSA-v2xr-wvrv-p969"],"modified":"2026-07-13T16:32:43.986836919Z","published":"2026-07-13T14:36:40.930968Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-45691"},{"type":"WEB","url":"https://github.com/explodinggradients/ragas/pull/1559"},{"type":"WEB","url":"https://github.com/vibrantlabsai/ragas/pull/1991"},{"type":"WEB","url":"https://github.com/vibrantlabsai/ragas/commit/b28433709cbedbb531db79dadcfbdbd3aa6adcb0"},{"type":"WEB","url":"https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerability"},{"type":"WEB","url":"https://github.com/explodinggradients/ragas/blob/e97886ac976465efb60e5949c5d69baf30cc811d/src/ragas/prompt/multi_modal_prompt.py#L202"},{"type":"PACKAGE","url":"https://github.com/vibrantlabsai/ragas"},{"type":"PACKAGE","url":"https://pypi.org/project/ragas"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-v2xr-wvrv-p969"}],"affected":[{"package":{"name":"ragas","ecosystem":"PyPI","purl":"pkg:pypi/ragas"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.2.3"},{"fixed":"0.3.0-rc1"}]}],"versions":["0.2.10","0.2.11","0.2.12","0.2.13","0.2.14","0.2.15","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/ragas/PYSEC-2026-3047.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}