CVE-2025-45691: Vibrantlabsai Ragas
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
Affected products
- Vibrantlabsai Ragas: from 0.2.3, up to and including 0.2.14
Published 2026-03-05. Last modified 2026-07-15.