An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
References
| Link | Resource |
|---|---|
| https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerability | Exploit Third Party Advisory |
| https://github.com/explodinggradients/ragas/blob/e97886ac976465efb60e5949c5d69baf30cc811d/src/ragas/prompt/multi_modal_prompt.py#L202 | Product |
| https://github.com/explodinggradients/ragas/pull/1559 | Exploit Issue Tracking Patch |
| https://github.com/vibrantlabsai/ragas/pull/1991 | Exploit Issue Tracking Patch Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2025-45691 | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2444875 | |
| https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-45691.json |
Configurations
History
No history.
Information
Published : 2026-03-05 19:16
Updated : 2026-07-15 02:17
NVD link : CVE-2025-45691
Mitre link : CVE-2025-45691
CVE.ORG link : CVE-2025-45691
JSON object : View
Products Affected
vibrantlabsai
- ragas
