CVE-2025-45691
EUVD-2025-20831505.03.2026, 19:16
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vibrantlabsai | ragas | 0.2.3 ≤ 𝑥 ≤ 0.2.14 |
𝑥
= Vulnerable software versions
References