CVE-2026-28797 | infiniflow ragflow up to 0.24.0 Text special elements used in a template engine (GHSA-vvwj-fvwh-4whx)
A vulnerability marked as critical has been reported in infiniflow ragflow up to 0.24.0. Impacted is an unknown function of the component Text Handler. This manipulation causes improper neutralization of special elements used in a template engine.
This vulnerability is handled as CVE-2026-28797. The attack can be initiated remotely. There is not any exploit available.