VDB
Sign up
HIGH7.5

PYSEC-2026-3047

RAGAS has an Arbitrary File Read vulnerability

Quick fix

PYSEC-2026-3047 — ragas: upgrade to the fixed version with the command below.

pip install --upgrade 'ragas>=0.3.0-rc1'

Details

An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ragas
Introduced in: 0.2.3Fixed in: 0.3.0-rc1
Fixpip install --upgrade 'ragas>=0.3.0-rc1'

References