Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2184453
AlmaLinux
5857
Alpaquita
15521
Alpine
4589
Android
3674
Azure Linux
17131
BellSoft Hardened Containers
744
Bitnami
9212
Chainguard
1019853
CleanStart
3432
CRAN
14
crates.io
2710
Debian
67360
Echo
6542
GHC
3
GIT
106316
GitHub Actions
55
Go
9147
Hackage
32
Hex
351
Julia
1713
Linux
29368
Mageia
6200
Maven
6998
MinimOS
142708
npm
228436
NuGet
1860
opam
29
openEuler
8674
openSUSE
14332
OSS-Fuzz
4003
Packagist
7036
Pub
11
PyPI
25074
Red Hat
23028
Rocky Linux
4229
Root
19463
RubyGems
4709
SUSE
23039
SwiftURL
59
TuxCare
9208
Ubuntu
64326
VSCode
21
Wolfi
287386
ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3475
PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
23 Jul
Fix available
Severity - 9.3 (Critical)
PYSEC-2026-3474
PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
23 Jul
Fix available
Severity - 9.3 (Critical)
GHSA-f4vv-55c2-5789
PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
20 Jul
Fix available
Severity - 9.3 (Critical)
GHSA-6x6h-qqr7-855w
PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
20 Jul
Fix available
Severity - 9.3 (Critical)
PYSEC-2026-2592
PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability
13 Jul
Fix available
Severity - 4.2 (Medium)
PYSEC-2026-2593
PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
13 Jul
Fix available
Severity - 7.5 (High)
PYSEC-2026-1539
PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
07 Jul
Fix available
Severity - 4.8 (Medium)
GHSA-8ffj-4hx4-9pgf
PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability
08 Apr
Fix available
Severity - 4.2 (Medium)
GHSA-mcww-4hxq-hfr3
PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
04 Apr
Fix available
Severity - 7.5 (High)
GHSA-v9w6-9hq9-33ch
PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
27 Jun 2025
Fix available
Severity - 4.8 (Medium)
PyPI - OSV