Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3475
  • PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 23 Jul
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3474
  • PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 23 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-f4vv-55c2-5789
  • PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 20 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-6x6h-qqr7-855w
  • PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 20 Jul
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-2592
  • PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability 13 Jul
  • Fix available
  • Severity - 4.2 (Medium)
PYSEC-2026-2593
  • PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1539
  • PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir 07 Jul
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8ffj-4hx4-9pgf
  • PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability 08 Apr
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-mcww-4hxq-hfr3
  • PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass 04 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-v9w6-9hq9-33ch
  • PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir 27 Jun 2025
  • Fix available
  • Severity - 4.8 (Medium)