Hkuds

Lightrag

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 22.09.2026 16:21:43
  • Zuletzt bearbeitet 22.09.2026 19:16:54

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an HTML sanitizer...

  • EPSS 0.22%
  • Veröffentlicht 22.09.2026 16:20:11
  • Zuletzt bearbeitet 28.09.2026 20:17:11

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying an IPv4 addr...

  • EPSS 0.36%
  • Veröffentlicht 22.09.2026 16:18:14
  • Zuletzt bearbeitet 22.09.2026 18:17:23

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A netwo...

  • EPSS 0.36%
  • Veröffentlicht 22.09.2026 16:16:36
  • Zuletzt bearbeitet 26.09.2026 00:16:37

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after the first misma...

  • EPSS 0.39%
  • Veröffentlicht 22.09.2026 16:13:53
  • Zuletzt bearbeitet 22.09.2026 19:16:54

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_serve...

  • EPSS 1.38%
  • Veröffentlicht 07.08.2026 20:09:49
  • Zuletzt bearbeitet 09.09.2026 21:02:22

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed doc...

  • EPSS 0.4%
  • Veröffentlicht 15.07.2026 14:14:41
  • Zuletzt bearbeitet 15.07.2026 18:15:13

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded...

  • EPSS 0.31%
  • Veröffentlicht 15.07.2026 14:12:45
  • Zuletzt bearbeitet 15.07.2026 18:15:13

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 08.04.2026 19:41:23
  • Zuletzt bearbeitet 24.07.2026 21:10:00

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.deco...