CVE-2025-6773Medium· 5.3▾ SunlitHKUDS LightRAG allows Path Traversal via function upload_to_input_dir
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of the file lightrag/api/routers/document_routes.py of the component File Upload. The manipulation of the argument file.filename leads to path traversal. It is possible to launch the attack on the local host. The identifier of the patch is 60777d535b719631680bcf5d0969bdef79ca4eaf. It is recommended to apply a patch to fix this issue.
lightrag-hku < 1.3.8Upgrade to a patched release:
lightrag-hku 1.3.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-30762High· 7.5LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
CVE-2026-39413Medium· 4.2lightrag-hku: JWT Algorithm Confusion Vulnerability
CVE-2026-61736Critical· 9.3LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection