Back to skill

Security audit

RAGFlow open-source Retrieval-Augmented Generation (RAG) engine — deployment, configuration, management, and troubleshooting.

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent RAGFlow deployment and administration guide, with real operational security risks to manage but no evidence of hidden or malicious behavior.

Safe to treat as documentation, but do not run the deployment commands blindly. Use a pinned RAGFlow release or commit, change the default MySQL and MinIO passwords before exposure, keep API keys out of shell history and version control, confirm any DROP/down -v/prune command before running it, and prefer an isolated host or container environment for Docker and source-build work.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:152
Finding

Unpinned Remote Source and Dependencies Are Installed and Executed

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:152-159; references/deployment.md:148-170
Vulnerability Type: Supply-chain exposure through mutable remote source and dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:152-159:

bash
git clone https://github.com/infiniflow/ragflow.git && cd ragflow
uv sync --python 3.12 && uv run python3 download_deps.py
docker compose -f docker/docker-compose-base.yml up -d
# Add to /etc/hosts: 127.0.0.1 es01 infinity mysql minio redis sandbox-executor-manager
source .venv/bin/activate && export PYTHONPATH=$(pwd)
bash docker/launch_backend_service.sh
# Separate terminal:
cd web && npm install && npm run dev

references/deployment.md:148-170:

bash
# 1. Clone and install Python deps
git clone https://github.com/infiniflow/ragflow.git
cd ragflow/
uv sync --python 3.12
uv run python3 download_deps.py
pre-commit install

# 2. Start infrastructure services
docker compose -f docker/docker-compose-base.yml up -d

# 3. Add to /etc/hosts
# 127.0.0.1  es01 infinity mysql minio redis sandbox-executor-manager

# 4. (If in China) Set HF mirror
# export HF_ENDPOINT=https://hf-mirror.com

# 5. Launch backend
source .venv/bin/activate
export PYTHONPATH=$(pwd)
bash docker/launch_backend_service.sh

# 6. Launch frontend (separate terminal)
cd web
npm install
npm run dev

Technical Analysis

The documented default workflow clones the mutable default branch of an external repository and immediately installs or executes its contents. It does not require a reviewed release tag or full commit SHA, verify a signed commit or release artifact, or document hash verification before execution.

The workflow executes several supply-chain-sensitive operations:

  • uv sync resolves and installs Python dependencies.
  • download_deps.py runs repository-controlled Python code a ...[truncated 2088 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require checkout of a reviewed release tag and preferably a full immutable commit SHA rather than the default branch.
  2. Verify signed Git tags or commits against trusted maintainer keys before running repository content.
  3. Publish and verify cryptographic hashes or signatures for downloaded models, archives, binaries, and container images.
  4. Pin container images by digest rather than relying only on mutable tags.
  5. Use committed lockfiles and frozen or locked dependency-installation modes for Python and Node.js.
  6. Disable package lifecycle scripts during initial inspection where practical, and explicitly review any scripts that must run.
  7. Review download_deps.py, pre-commit configuration, Compose definitions, and launch scripts before execution.
  8. Perform installation in a disposable, isolated environment using an unprivileged account with minimal filesystem and network access.
  9. Avoid granting the installation process unrestricted Docker daemon access unless necessary.
  10. Add automated software composition analysis, artifact provenance verification, and vulnerability scanning to the deployment procedure.

T09 · Insecure Skill Coding Practices

Warning
Location
references/deployment.md:61
Finding

Publicly Documented Shared Default Passwords for Privileged Services

Content
View full analysis

Vulnerability Details

File Location: references/deployment.md:61-62
Vulnerability Type: Insecure default credentials and credential reuse
Risk Level: Medium

Vulnerable Code

text
| `MYSQL_PASSWORD` | MySQL root password | `infini_rag_flow` |
| `MINIO_PASSWORD` | MinIO access password | `infini_rag_flow` |

Technical Analysis

The deployment reference documents a fixed, publicly known password for the MySQL root account and the MinIO access account. The same password is reused across two distinct services, increasing the effect of credential disclosure or service exposure.

The deployment procedure does not explicitly require operators to replace these defaults with unique, randomly generated credentials before first startup. Consequently, a deployment created directly from the instructions may retain predictable credentials. Public knowledge of these values eliminates password secrecy and makes authentication dependent primarily on whether the relevant service is network-accessible.

The audited documentation does not establish that MySQL or MinIO is exposed publicly by default. Exploitation therefore depends on those services becoming reachable through Compose port publication, host networking, reverse-proxy changes, firewall errors, lateral access from another compromised container, or subsequent deployment modifications.

Attack Path

  1. An operator deploys RAGFlow without changing MYSQL_PASSWORD and MINIO_PASSWORD.
  2. MySQL or MinIO becomes reachable by an attacker due to network exposure, configuration drift, lateral movement, or access from another compromised workload.
  3. The attacker attempts authentication using the publicly documented password infini_rag_flow.
  4. If the default credential remains active, the attacker authenticates to the exposed service.
  5. Through MySQL root access, the attacker may read or modify application database records and configuration stored in the ...[truncated 965 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove usable static password defaults and replace them with explicit placeholders that cause deployment to fail until configured.
  2. Generate separate, cryptographically random credentials for MySQL and MinIO before first startup.
  3. Do not reuse passwords between services or environments.
  4. Store credentials through Docker secrets, an orchestrator secret facility, or an external secret manager rather than committing them to configuration files.
  5. Add startup validation that rejects known defaults, empty values, and common placeholder credentials.
  6. Bind MySQL and MinIO management ports only to required internal networks and avoid publishing them to public interfaces.
  7. Apply firewall rules and service-specific least-privilege policies.
  8. Avoid using the MySQL root account for routine application access; create a dedicated database user with only the required schema privileges.
  9. Assign a restricted MinIO policy to the application account rather than broad administrative permissions.
  10. Rotate any existing deployments that may have used these defaults and inspect authentication logs for attempts involving the documented password.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
- **Deploying / troubleshooting deployment** → [references/deployment.md](references/deployment.md)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 27)May include surrounding context.

docker compose -f docker-compose.yml up -d

For GPU acceleration:

sed -i '1i DEVICE=gpu' .env

docker compose -f docker-compose.yml up -d

text

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployment.md (reported line 126)May include surrounding context.

docker compose -f docker-compose.yml up -d

For GPU acceleration:

sed -i '1i DEVICE=gpu' .env

docker compose -f docker-compose.yml up -d

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to place live LLM API keys directly into a configuration template file and restart services, but provides no warning about secret storage, access controls, or avoiding commits to source control. This increases the risk of credential leakage through repository commits, backups, shared hosts, screenshots, or overly permissive file access in Docker-based deployments.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

user_default_llm: factory: "OpenAI" # or "DeepSeek", "Gemini", etc. api_key: "sk-..." base_url: "https://api.openai.com/v1/"

text
3. Run `docker compose -f docker-compose.yml up -d` to apply.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deployment.md (reported line 97)May include surrounding context.

user_default_llm: factory: "OpenAI" # or "DeepSeek", "Gemini", etc. api_key: "sk-..." base_url: "https://api.openai.com/v1/"

text
3. Run `docker compose -f docker-compose.yml up -d` to apply.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
| ARM64 platform | Build Docker image from source (no official ARM64 image) |
| Port conflict | Change `80:80` to `<PORT>:80` in `docker-compose.yml` |
| Elasticsearch exits with 137 | Increase Docker memory allocation |
| `vm.max_map_count` too low | `sudo sysctl -w vm.max_map_count=262144` |

## API & SDK

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to pass an API key directly as a CLI argument in CREATE MODEL PROVIDER <provider_name> <provider_key>; and gives an example with a raw secret. CLI arguments are commonly exposed through shell history, process listings, terminal logs, and CI job output, so this guidance can lead to accidental credential disclosure even if the underlying feature is legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The reference documents destructive DROP MODEL PROVIDER usage without any caution, confirmation guidance, or note about operational consequences. In admin-oriented tooling, terse destructive commands increase the chance of accidental deletion or misuse, which can disrupt service configuration and break dependent workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The IMPORT examples show local file paths being submitted to the system without warning that file metadata and document contents may be uploaded to the server for processing. Users may unknowingly transmit sensitive documents or reveal filesystem structure, which is especially relevant in a RAG ingestion workflow where content is parsed, stored, and indexed remotely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deployment.md (reported line 105)May include surrounding context.

user_default_llm: factory: "DeepSeek" api_key: "sk-..." base_url: "https://api.deepseek.com/v1"

text

## Port Configuration

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/deployment.md (reported line 213)May include surrounding context.

Temporary fix:

bash
sudo sysctl -w vm.max_map_count=262144

Permanent fix (add to /etc/sysctl.conf):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting guidance recommends docker system prune -a, which can remove unused images, containers, networks, and build cache broadly across the host. In a deployment reference, this can cause accidental service disruption or loss of locally needed artifacts if operators run it without understanding the scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.