Python

ragas

Latest secure version 0.2.2

Evaluation framework for RAG and LLM applications

Apache License Version 2.0, January 2004 http://www.apache.org/licenses/ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION 1. Definitions. "License" shall mean the terms and conditions for use, reproduction, and distribution as defined by Sections 1 through 9 of this document. "Licensor" shall mean the copyright owner or entity authorized by the copyright owner that is granting the License. "Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means

All Versions

Vulnerabilities (Public)

Known vulnerabilities and security issues detected in the extension's dependencies and code.

Vulnerability IDAdvisoryAffected Versions
CVE-2025-45691RAGAS has an Arbitrary File Read vulnerability
High
>= 0.2.3, < 0.3.0-rc1
CVE-2026-6587Affected versions of the ragas package are vulnerable to Server-Side Request Forgery due to insufficient validation of attacker-controlled URL and file path arguments in the Collections Module. The fl…
Low
>=0.2.3,<=0.4.3

Safety Discovered Vulnerabilities

Additional security issues found by Safety, exclusive to our platform.

Safety discovered vulnerability data is available for Enterprise customers

Book a call with us to see Safety in action.

Vulnerable Functions

Functions linked to known vulnerabilities in this package.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.