HIGH7.5
PYSEC-2026-3047
RAGAS has an Arbitrary File Read vulnerability
Quick fix
PYSEC-2026-3047 — ragas: upgrade to the fixed version with the command below.
pip install --upgrade 'ragas>=0.3.0-rc1'Details
An Arbitrary File Read vulnerability exists in the ImageTextPromptValue class in Exploding Gradients RAGAS v0.2.3 to v0.2.14. The vulnerability stems from improper validation and sanitization of URLs supplied in the retrieved_contexts parameter when handling multimodal inputs.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-45691[ADVISORY]
- https://github.com/explodinggradients/ragas/pull/1559[WEB]
- https://github.com/vibrantlabsai/ragas/pull/1991[WEB]
- https://github.com/vibrantlabsai/ragas/commit/b28433709cbedbb531db79dadcfbdbd3aa6adcb0[WEB]
- https://adithyanak.com/ragas-v0214-arbitrary-file-read-vulnerability[WEB]
- https://github.com/explodinggradients/ragas/blob/e97886ac976465efb60e5949c5d69baf30cc811d/src/ragas/prompt/multi_modal_prompt.py#L202[WEB]
- https://github.com/vibrantlabsai/ragas[PACKAGE]
- https://pypi.org/project/ragas[PACKAGE]
- https://github.com/advisories/GHSA-v2xr-wvrv-p969[ADVISORY]