Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-xpjq-3w4w-w5wr
  • PyPI/lightrag-hku
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content yesterday
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-vv3m-f8x4-7377
  • PyPI/lightrag-hku
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-frch-4w6v-q5xx
  • PyPI/lightrag-hku
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks yesterday
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-c759-cx9p-mrwq
  • PyPI/lightrag-hku
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function yesterday
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-hrmj-7rvj-4hg8
  • PyPI/lightrag-hku
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses yesterday
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-3475
  • PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 23 Jul
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-3474
  • PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 23 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-f4vv-55c2-5789
  • PyPI/lightrag-hku
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection 20 Jul
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-6x6h-qqr7-855w
  • PyPI/lightrag-hku
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests 20 Jul
  • Fix available
  • Severity - 9.3 (Critical)
PYSEC-2026-2592
  • PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability 13 Jul
  • Fix available
  • Severity - 4.2 (Medium)
PYSEC-2026-2593
  • PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass 13 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1539
  • PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir 07 Jul
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-8ffj-4hx4-9pgf
  • PyPI/lightrag-hku
lightrag-hku: JWT Algorithm Confusion Vulnerability 08 Apr
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-mcww-4hxq-hfr3
  • PyPI/lightrag-hku
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass 04 Apr
  • Fix available
  • Severity - 7.5 (High)
GHSA-v9w6-9hq9-33ch
  • PyPI/lightrag-hku
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir 27 Jun 2025
  • Fix available
  • Severity - 4.8 (Medium)