#RAGFlow
개인 메모나 문서 검색을 셀프호스팅 환경에서 구축할 수 있는 도구들이 잘 정리되어 있네요. AnythingLLM처럼 로컬 모델과 다양한 벡터 DB를 연동해 개인 지식베이스를 가볍게 꾸리거나, RAGFlow처럼 복잡한 문서를 파싱해 연동할 때 참고하기 좋습니다.

#AI #개발

https://shop.zimaspace.com/blogs/tech-ai-hub/top-self-hosted-ai-search-tools-2026
September 30, 2026 at 3:59 AM
Today's AI brief: DeepSeek prices climb as RAGFlow rewrites in Go. Two shifts worth noting from our daily tracking.

https://olud.ai/news/2026-09-29.html

#AI #OpenSource #AINews
September 29, 2026 at 10:02 AM
ragflow by @infiniflowai (⭐️ 91363)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
September 27, 2026 at 6:57 PM
10. RAGFlow — Build AI systems around your own documents

RAGFlow focuses heavily on Retrieval-Augmented Generation.

The idea is simple:

Instead of forcing an AI model to answer only from what it learned during training, you connect your own documents and knowledge.
September 25, 2026 at 12:00 PM
ragflow by @infiniflowai (⭐️ 91093)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
September 21, 2026 at 12:17 PM
📝 Neuer Blog-Beitrag: Open-Source-Highlights September 2026: 7 Projekte, die du kennen solltest

VoiceBox, Open Design, Scrapling, OpenMontage, Agent Reach, World Monitor und RAGFlow – die spannendsten Open-Source-Projekte im September und warum sie jetzt re…

#OpenSource #GitHubTrending #KI
Open-Source-Highlights September 2026: 7 Projekte, die du kennen solltest
VoiceBox, Open Design, Scrapling, OpenMontage, Agent Reach, World Monitor und RAGFlow – die spannendsten Open-Source-Projekte im September und warum sie jetzt relevant sind.
blog.saaro.net
September 19, 2026 at 7:16 AM
LiteLLM: CVE-2026-42271 chained with CVE-2026-48710 for remote code execution, then credential theft, database access and cryptomining. RAGFlow: provider credentials intercepted through application hooks.
September 12, 2026 at 7:30 PM
🚀 GitHub Intelligence Drop

ragflow (Go • 🟢)
⭐ 90.1K → https://github.com/infiniflow/ragflow

mermaid (TypeScript • 🟢)
⭐ 90.1K → https://github.com/mermaid-js/mermaid

⚡ Only signal. Zero noise.
September 6, 2026 at 2:13 AM
ragflow by @infiniflowai (⭐️ 89819)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
September 1, 2026 at 12:38 PM
ragflow by @infiniflowai (⭐️ 89554)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
August 29, 2026 at 7:44 AM
ragflow by @infiniflowai (⭐️ 89492)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
August 28, 2026 at 1:25 PM
RAGFlow turns messy documents into clear answers for your AI tools.

- Reads complex files like contracts and reports
- Extracts accurate answers from unstructured data
- Open source, so you can self-host it

Learn More about this levitating project:
osp.fyi/ragflow
August 28, 2026 at 3:06 AM
When AI Infrastructure Becomes the Target: Attacks Observed on LiteLLM, RAGFlow, and Kestra
## 1. Basic Information * **Article Title** : When AI infrastructure becomes the target: Securing gateways and control points * **Publisher** : Microsoft Security Research * **Publication Date** : 2026-08-26 * **Source** : Microsoft Security Research * **Related Sources** : CVE-2026-42271, CVE-2026-48710, CVE-2026-49869 * **Related Malware, Threat Groups, CVEs, and Products** : XMRig, CVE-2026-42271, CVE-2026-48710, CVE-2026-49869, CVE-2026-45312, CVE-2026-28797, CVE-2026-24770, CVE-2025-68700, LiteLLM, RAGFlow, Kestra, Azure Database for PostgreSQL, Docker * **Severity** : High ## 2. Executive Summary AI gateways, RAG systems, and workflow platforms—which act as central control points holding model keys, database credentials, and container permissions—were compromised and abused for credential theft, persistence, and cryptomining. ## 3. Attack Flow ### LiteLLM Compromise 1. Command execution is achieved through an externally exposed LiteLLM gateway. Microsoft evaluates this as consistent with a chain of CVE-2026-42271 and CVE-2026-48710, though it is not definitively confirmed. 2. The attacker reads `/proc/1/environ`, which holds the environment variables of the PID 1 process inside the container, to gather model provider API keys, master keys, and `DATABASE_URL`. 3. Python, curl, and wget are used as alternatives to place an ELF binary in `/tmp` and execute it with a service-like name. 4. An XMRig-based miner is deployed, and competing miners are removed. 5. The attacker connects to the LiteLLM PostgreSQL database using the retrieved `DATABASE_URL` to harvest and exfiltrate model configurations and virtual keys. 6. Persistence is established using the service account's `authorized_keys`, cron, hidden files, and immutable attributes. ### RAGFlow Compromise 1. An OAST callback originates from the HTTP client of the RAGFlow application itself, and code execution is observed within the same service context a few days later. 2. The attacker places a hidden Python hook under the application path to alter startup and import routes. 3. The TenantLLM configuration handling is wrapped to steal API keys and model information for LLM providers registered after infection. 4. Microsoft does not confirm the specific CVE that caused the initial breach, even with low confidence. ### Kestra Compromise 1. Microsoft assesses the authentication bypass vulnerability CVE-2026-49869 as a high-confidence initial vector. 2. A worker spawns a shell from a malicious workflow. 3. The `Config.Env` of other containers is enumerated via a mounted Docker socket to harvest potential cloud keys, database passwords, and API tokens. 4. XMRig is deployed, and subsequent script outputs are stored in the Kestra KV API. ## 4. Threat Actor Position and Execution Location * External attackers targeting internet-accessible AI management planes and APIs. * Operating within the application and worker execution contexts of LiteLLM, RAGFlow, and Kestra after compromise. ## 5. Visibility for Victims and Administrators ### Victims * Regular AI users have difficulty noticing the compromise. In RAGFlow, configuration operations continue normally while new API keys are being stolen. ### Administrators * Observable indicators include the launch of shells, Python, curl, and wget under AI service processes, execution from `/tmp`, access to the Docker socket, and outbound traffic following API key registration. * CPU load from cryptomining and modifications to `authorized_keys`, cron, or application startup files may also be visible. ## 6. Success and Failure Conditions ### Success Conditions * Attackers can reach vulnerable or improperly exposed AI management planes. * AI services have access to model keys, database connection strings, virtual keys, and environment variables of other containers. * Outbound communication from service containers, execution in `/tmp`, and the use of Docker sockets are not sufficiently restricted. ### Failure Conditions & Risk Mitigation * AI management planes are kept private, with authentication, patching, and source IP restrictions applied. * API keys are not constantly held in the process environment, utilizing dedicated secret stores and the principle of least privilege instead. * Outbound traffic is denied by default, temporary directories are configured with `noexec`, and Docker sockets are not mounted to block subsequent activities. ## 7. What Happens Upon Success * Theft of model provider API keys, LiteLLM master keys, virtual keys, and database credentials. * Persistent access to the AI infrastructure and other containers. * Unauthorized use of computing resources for cryptomining. * Continuous theft of newly registered LLM credentials in RAGFlow after infection. ## 8. Observable Logs * **Email** : Not directly related. * **Proxy/SWG/DNS** : External access to AI management planes; communications to OAST, C2, raw IPs, and mining pools. Correlating communications to sslip.io, OAST domains, and non-standard ports with asset context. * **Endpoint/EDR** : Bash, sh, python, curl, or wget spawned by AI service parent processes; references to `/proc/1/environ`, execution from `/tmp`, chmod, chattr, and modifications to `authorized_keys`, cron, or RAGFlow startup files; Docker socket enumeration, XMRig deployment, and MSR module loading. * **Identity/IdP** : Subsequent use of stolen model keys, virtual keys, and service principals. * **SaaS/Cloud** : Abnormal usage and billing of model provider APIs, unusual connections to Azure PostgreSQL, and Kestra workflow/KV operations. * **Network** : Outbound connections from AI services to raw IPs, OAST, C2, and Monero pools. ## 9. Attack Success Determination * **Attack Attempt Observed (Success Unconfirmed)** : Scanning of the AI management plane, SSRF-like OAST callbacks, or vulnerability payloads confirmed, but no child processes or access to secrets observed. * **Initial Execution Confirmed** : Shells or Python spawned with AI services/workers as parent processes, or execution originating from malicious workflows. * **Information Theft or Session Compromise Confirmed** : Collection and external exfiltration of `/proc/1/environ`, LiteLLM database, RAGFlow LLM configurations, and Docker `Config.Env`. * **Subsequent Compromise Confirmed** : Persistence via `authorized_keys`, cron, or application hooks; XMRig execution; or discovery of secrets in other containers. ## 10. Investigation Playbook * **Trigger** : Shell/interpreter spawned from AI service parent processes, access to `/proc/1/environ` or Docker sockets, or detection of vulnerability exploitation against management planes. * **Initial Verification** : Check target products, versions, exposure status, and authentication settings. Align parent-child processes, container IDs, workflow/API audits, and outbound communications on the same timeline. * **Endpoints** : Inspect `/tmp`, `authorized_keys`, cron, immutable attributes, RAGFlow startup and import paths, and XMRig artifacts. * **Authentication/Cloud** : Check usage history of model provider keys, LiteLLM virtual keys, database connection info, and service principals; revoke exposed candidates. * **Subsequent Operations** : Investigate unauthorized use of other containers enumerated via Docker sockets, databases, and model provider sides. * **Containment** : Isolate and patch the management plane, and recreate containers from trusted images. Rotate potentially exposed keys, tokens, and database credentials, and restrict outbound traffic. * **Judgment Categories** : Separate into scanning only, app-origin execution, access to secrets, external exfiltration, and persistence/resource abuse. ## 11. Defense and Detection Ideas * **Single Event** : Prioritize events where shells, downloaders, or interpreters are spawned by AI service parent processes and reference `/proc/1/environ`, `DATABASE_URL`, or LiteLLM table names. * **Timeline Correlation** : Correlate management plane access -> app-origin shell execution -> access to secrets -> outbound communication -> persistence/miner execution as a series of events on the same container and host. * **Hunting** : Inventory external exposure of AI gateways, RAG, and workflow platforms, Docker socket mounting, and secrets held within process environments. * **Lack of Logs** : Assessing success is difficult without process lineage within containers, file modifications, outbound DNS/HTTP traffic, workflow audits, and model provider API audits. * **Priority Mitigations** : Make management planes private and apply rapid patches. Use managed secret stores, team-specific virtual keys, and least-privilege databases. Implement default-deny outbound traffic, unexposed Docker sockets, and temporary directories with `noexec`. ## 12. Facts / Inference / Hypothesis ### Facts * Microsoft observed compromise activities across LiteLLM, RAGFlow, and Kestra environments, including credential theft, persistence, and resource abuse. * In LiteLLM, `/proc/1/environ` and PostgreSQL model configuration/virtual key tables were collected. * In RAGFlow, hooks were placed in TenantLLM configuration handling to collect API keys registered post-infection. * In Kestra, workflow-origin shell execution, enumeration of `Config.Env` via Docker sockets, and XMRig deployment were observed. ### Inference * AI infrastructure must be treated as Tier-0 equivalent control planes where secrets, execution privileges, and data connections concentrate, rather than simple applications. * Relationships between execution from AI service parent processes, access to secrets, and outbound communications serve as long-term effective detection axes, beyond product-specific IOCs. ### Hypothesis * Orderly exception handling and fallback mechanisms align with AI-assisted development, but Microsoft does not present them as evidence of specific authors or development methods. ## 13. MITRE ATT&CK Mapping * **T1190 Exploit Public-Facing Application (High)** : Management planes of externally exposed AI workloads serve as initial entry points. Confidence in individual CVEs varies by product. * **T1552.001 Unsecured Credentials: Credentials In Files (High)** : Searching for secrets from process environment variables, database configurations, and container environment variables. * **T1059.004 Command and Scripting Interpreter: Unix Shell (High)** : Gateway/workflow-origin shell execution observed. * **T1098.004 Account Manipulation: SSH Authorized Keys (High)** : Modifications to `authorized_keys` for LiteLLM service accounts observed. * **T1496 Resource Hijacking (High)** : XMRig/RandomX-based cryptomining observed. ## 14. Unknowns / Further Investigation * Specific CVEs used for initial entry in LiteLLM and RAGFlow have not been definitively identified. * The number of victim organizations, threat actor attributes, and the scope of subsequent use of stolen keys are not publicly disclosed. ## 15. Impact and Considerations for Global Enterprises and SOCs As the external exposure of proof-of-concept and internal AI infrastructures increases globally, organizations should avoid treating LiteLLM and similar tools with lower priority than standard web applications. SOCs should monitor parent-child processes, access to secrets, container boundaries, and key usage on model provider sides as a single unified attack chain. ## 16. Summary by Target Audience * **For SOCs** : Correlate shell launches from AI service parent processes, `/proc/1/environ` reads, Docker socket usage, outbound communications, and persistence; track up to unauthorized model key usage. * **For Administrators** : Make management planes private and patched; apply secret stores, least-privilege databases, outbound traffic controls, and Docker socket isolation. * **For Users** : The underlying infrastructure can be compromised and registered API keys stolen even without direct actions by AI service users.
dev.to
August 27, 2026 at 11:10 PM
Fresh evidence

Microsoft observed LiteLLM, RAGFlow, and Kestra compromises. The LiteLLM chain ran from secret harvesting and database collection to persistence and cryptomining preparation.
August 27, 2026 at 2:39 PM
Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency
Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency
Hackers are increasingly turning AI platforms into a doorway to valuable corporate systems. New Microsoft research shows that exposed AI gateways, retrieval tools, and workflow services can give intruders a path to provider credentials, databases, container environments, and powerful computing resources. The activity spans three different targets: LiteLLM, RAGFlow, and Kestra. Although the entry points differed, the attackers followed a familiar money-making playbook: steal secrets, retain access, and use compromised servers for cryptocurrency mining or other downstream abuse. These services now act as high-value control points. The findings also underline a shift in attacker interest. Microsoft said in a report shared with Cyber Security News (CSN) that rather than going after only end users or conventional cloud servers, criminals are probing the infrastructure that connects applications to large language models, databases, and automation. For security teams, unexplained spikes in AI consumption deserve the same urgency as the sudden bills seen in  AI token jacking incidents . Hackers Exploit AI Infrastructure In the LiteLLM case, Microsoft assessed with high confidence that attackers likely exploited an exposed gateway through a chain involving CVE-2026-42271 and CVE-2026-48710. The first payload read the environment of the container’s main process and searched for API keys, tokens, passwords, and database details. It then sent the results outward using tools, giving the operators fallback options if a particular utility or outbound route was blocked. LiteLLM gateway compromise – attack chain (Source – Microsoft) Attackers next retrieved an ELF payload, placed it in a temporary location, and named it to resemble a normal Linux service. They checked the host, inspected open ports, looked for competing miners, and accessed LiteLLM’s PostgreSQL-backed records. The pattern mirrors earlier attacks on container environments, where exposed management interfaces can become a shortcut to host access. In a related case,  Docker endpoint mining campaign  showed how cryptojackers steal secrets, add access mechanisms, and remove rival miners after entering a cloud workload. RAGFlow faced a different form of abuse. Microsoft observed possible server-side request probing, followed days later by code execution and a hidden Python hook added to the application’s LLM configuration path. Each time an administrator configured a provider, the hook could silently capture the API key, model name, provider type, and endpoint information. Persistence and Mining Risks In the Kestra incident, attackers likely exploited CVE-2026-49869, a critical authentication-bypass flaw, to create a malicious workflow and make the worker run shell commands. They examined the Docker socket and container environment data, then downloaded and ran XMRig to mine Monero using the victim’s CPU. Persistence made each intrusion harder to clean up. Microsoft recorded service-account SSH key changes, cron manipulation, hidden temporary relays, service-like names, restart loops, and immutable file attributes. Database access and credential collection (Source – Microsoft) RAGFlow’s altered startup path could reload its credential-stealing hook when the service restarted, while the miner in Kestra was launched to survive the original shell session. The immediate response should be to patch exposed AI services, rotate any keys connected to a reachable or compromised gateway, and review database and provider-account activity. Teams should also look for unexpected shell or Python processes launched by AI applications, especially where they coincide with secret access, writes to application files, or unusual outbound connections. Microsoft recommends treating AI gateways as stores for the most sensitive secrets. Organizations should require authentication for application and management surfaces, keep admin ports off the public internet, use separate limited-purpose service accounts, and place databases behind private, restrictive network paths. RAGflow compromise – attack chain (Source – Microsoft) Provider keys should be stored in a managed secrets system rather than process environment variables, with separate virtual keys and spending limits for teams. Finally, outbound connections should be denied by default and limited to required services. Logging DNS callbacks, raw-IP traffic, changes to SSH authorized_keys and cron jobs, and execution from writable temporary folders can expose a connected attack chain before stolen access turns into sustained mining or expensive model misuse. Readers tracking  AI credential theft plugins  can see why fast revocation and usage monitoring matter once a key leaves its intended environment. Indicators of compromise (IoCs):- Type Indicator Description IPv4 address 45.150.109[.]151 Campaign-associated infrastructure IPv4 address and port 135.125.10[.]56:19888 Campaign-associated infrastructure IPv4 address and port 172.232.38[.]92:32991 Campaign-associated infrastructure IPv4 address 47.86.197[.]116 Campaign-associated infrastructure IPv6 address 2001:41d0:701:1100::adfd Campaign-associated infrastructure Domain 45.150.109.151.sslip[.]io DNS rebinding infrastructure used in the campaign Domain and port auto.c3pool[.]org:443 Monero mining-pool infrastructure Domain yosemite[.]jp Out-of-band callback infrastructure Domain gobygo[.]net Out-of-band callback infrastructure Domain oast[.]me Out-of-band callback infrastructure Domain oast[.]pro Out-of-band callback infrastructure Domain oast[.]fun Out-of-band callback infrastructure Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs:  Integrate TI Lookup in your SOC The post Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency appeared first on Cyber Security News .
cybersecuritynews.com
August 27, 2026 at 1:19 PM
Microsoft researchers observed attacks on three AI workloads: LiteLLM, RAGFlow & Kestra. The intrusion paths varied, but the objectives were similar: the attackers sought to steal credentials, establish persistence, & monetize compromised compute resources. www.microsoft.com/en-us/securi...
August 27, 2026 at 8:20 AM
Microsoft found three separate attacks — via LiteLLM, RAGFlow, and Kestra — turning AI tools into launchpads for cryptomining and credential theft
Microsoft finds three attacks turning AI control planes into launchpads – 4sysops
Microsoft has documented compromises of LiteLLM, RAGFlow, and Kestra that turned AI infrastructure into a pathway for credential theft, persistence, data access
4sysops.com
August 27, 2026 at 2:50 AM
ragflow by @infiniflowai (⭐️ 89002)

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superi...

#go
August 22, 2026 at 4:33 AM
📢 New #updates · 19 Aug #8

· RAGFlow v0.27.0 — Added new model provider and memory update fix
· clickhouse v26.5.7.64-stable
· Wekan v11.03
August 19, 2026 at 9:51 AM
CVE-2026-75898 - RAGFlow
CVE ID : CVE-2026-75898

Published : Aug. 18, 2026, 2:24 p.m. | 12 minutes ago

Description : RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The compo...
CVE-2026-75898 - RAGFlow < 0.26.3 - Server-Side Request Forgery via Agent Invoke Component
RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get, requests.post, or requests.put without calling the shared assert_url_is_safe validator or pinning the resolved address, unlike …
cvefeed.io
August 18, 2026 at 3:03 PM
Drop in a contract: OCR restores clauses, RAGFlow retrieves policy, Semantica maps the evidence, and Astron RPA writes 6 fields into an ERP review draft. The real run stops for human review—final submit stays disabled.
https://github.com/FenjuFu/astron-images/tree/main/astron-ragflow-semantica-contr
August 16, 2026 at 11:02 AM
RAGFlow's open-source RAG engine now supports DeepSeek v4 and Gemini 3 Pro. Template-based chunking and agentic workflows reduce LLM hallucinations. Self-host with Docker, 4 CPU cores, 16 GB RAM.
[GitHub Trending] infiniflow/ragflow
Four Signals — The Wire
www.foursignals.dev
August 15, 2026 at 1:00 PM
8. https://github.com/github/spec-kit - Python, 1147 stars today
9. https://github.com/lightningpixel/modly - TypeScript, 580 stars today
10. https://github.com/infiniflow/ragflow - Go, 474 stars today
11. https://github.com/cursor/plugins - TypeScript, 54 stars today
12 […]
Original post on backend.newsmast.org
backend.newsmast.org
August 14, 2026 at 1:01 PM
RAGFlow's latest release adds agent memory and multi-channel chat to its open-source RAG engine. Supports Confluence, S3, Google Drive ingestion with grounded citations. Self-hosted with Docker (4 CPU, 16 GB RAM).
[GitHub Trending] infiniflow/ragflow
Four Signals — The Wire
www.foursignals.dev
August 13, 2026 at 1:00 PM
📦 infiniflow / ragflow
⭐ 87,371 (+85)
🗒 Go

RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superior context layer for LLMs
GitHub - infiniflow/ragflow: RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superior context layer for LLMs
RAGFlow is a leading open-source Retrieval-Augmented Generation (RAG) engine that fuses cutting-edge RAG with Agent capabilities to create a superior context layer for LLMs - infiniflow/ragflow
github.com
August 13, 2026 at 3:16 AM