RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superior context layer for LLMs
fix: upgrade crawl4ai to 0.8.0 (CVE-2026-26217) (#15415)
## Summary Upgrade crawl4ai from 0.7.6 to 0.8.0 to fix CVE-2026-26217. ## Vulnerability | Field | Value | |-------|-------| | **ID** | CVE-2026-26217 | | **Severity** | CRITICAL | | **Scanner** | trivy | | **Rule** | `CVE-2026-26217` | | **File** | `uv.lock` | | **Assessment** | Likely exploitable | **Description**: Crawl4AI Has Local File Inclusion in Docker API via file:// URLs ## Evidence **Scanner confirmation**: trivy rule `CVE-2026-26217` flagged this pattern. **Production code**: This file is in the production codebase, not test-only code. ## Threat Model Context This is a web service - vulnerabilities in request handlers are directly exploitable by remote attackers. ## Changes - `pyproject.toml` - `uv.lock` ## Verification - [x] Build passes - [x] Scanner re-scan confirms fix - [x] LLM code review passed --- *This change addresses a pattern flagged by static analysis. The code path handles user-influenced input and the fix reduces the attack surface against both manual and automated exploitation.* --- *Automated security fix by [OrbisAI Security](https://orbisappsec.com)*
O
OrbisAI Security committed
b4c8711d515bc741dbd3b54eb743f0be2fc772fb
Parent: a28a0c6
Committed by GitHub <noreply@github.com>
on 5/29/2026, 1:38:41 PM