PatchSiren

vibrantlabsai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW vibrantlabsai CVE published 2026-04-20

CVE-2026-6587

A security flaw has been discovered in vibrantlabsai RAGAS up to 0.4.3. The affected element is the function _try_process_local_file/_try_process_url of the file src/ragas/metrics/collections/multi_modal_faithfulness/util.py of the component Collections Module. Performing a manipulation of the argument retrieved_contexts results in server-side request forgery. The attack can be initiated remotely. The exp [truncated]

HIGH Vibrantlabsai CVE published 2026-03-05

CVE-2025-45691

CVE-2025-45691 is an Arbitrary File Read vulnerability in the ImageTextPromptValue class of Exploding Gradients RAGAS versions 0.2.3 through 0.2.14. This vulnerability arises from inadequate validation and sanitization of URLs provided in the retrieved_contexts parameter when handling multimodal inputs. The vulnerability has a CVSS score of 7.5 and is classified as HIGH severity. The CVE was published on [truncated]