CVE-2026-86062
- EPSS 0.25%
- Veröffentlicht 22.09.2026 16:21:43
- Zuletzt bearbeitet 22.09.2026 19:16:54
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer...
CVE-2026-85740
- EPSS 0.22%
- Veröffentlicht 22.09.2026 16:20:11
- Zuletzt bearbeitet 28.09.2026 20:17:11
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 addr...
CVE-2026-85734
- EPSS 0.36%
- Veröffentlicht 22.09.2026 16:18:14
- Zuletzt bearbeitet 22.09.2026 18:17:23
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A netwo...
CVE-2026-85725
- EPSS 0.36%
- Veröffentlicht 22.09.2026 16:16:36
- Zuletzt bearbeitet 26.09.2026 00:16:37
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after the first misma...
CVE-2026-85709
- EPSS 0.39%
- Veröffentlicht 22.09.2026 16:13:53
- Zuletzt bearbeitet 22.09.2026 19:16:54
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_serve...
CVE-2026-61808
- EPSS 1.38%
- Veröffentlicht 07.08.2026 20:09:49
- Zuletzt bearbeitet 09.09.2026 21:02:22
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed doc...
CVE-2026-61740
- EPSS 0.4%
- Veröffentlicht 15.07.2026 14:14:41
- Zuletzt bearbeitet 15.07.2026 18:15:13
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded...
CVE-2026-61736
- EPSS 0.31%
- Veröffentlicht 15.07.2026 14:12:45
- Zuletzt bearbeitet 15.07.2026 18:15:13
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist...
CVE-2026-39413
- EPSS 0.17%
- Veröffentlicht 08.04.2026 19:41:23
- Zuletzt bearbeitet 24.07.2026 21:10:00
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.deco...