CVE-2025-51462 | RAGFlow 0.17.2 api.apps.dialog_app.set_dialog assistant greeting cross site scripting
A vulnerability categorized as problematic has been discovered in RAGFlow 0.17.2. Affected by this issue is the function api.apps.dialog_app.set_dialog. Such manipulation of the argument assistant greeting leads to cross site scripting.
This vulnerability is listed as CVE-2025-51462. The attack may be performed from remote. There is no available exploit.