RAGFlow is an open-source RAG engine based on deep document understanding for InfiniFlow. The RAGFlow 0.11.0 version has a command injection vulnerability, which stems from a lack of comprehensive input validation or cleaning, resulting in a remote code execution (RCE) vulnerability in the add_llm function of llm_app.py.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021. Other reference:None