---
id: CVE-2026-61808
title: LightRAG provides simple and fast retrieval-augmented generation
summary: >-
  LightRAG provides simple and fast retrieval-augmented generation. Through
  version 1.5.4, the LightRAG API server binds to all network interfaces with
  authentication disabled by default, allowing an unauthenticated network
  attacker to rea…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
published: '2026-08-07'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:02:22.660'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61808'
references:
  - url: >-
      https://github.com/HKUDS/LightRAG/commit/0bd102401b4b28a02664e5b6af476bf7a4470292
    label: security-advisories@github.com
  - url: 'https://github.com/HKUDS/LightRAG/security/advisories/GHSA-mmg5-8x8q-v934'
    label: security-advisories@github.com
  - url: 'https://github.com/HKUDS/LightRAG/security/advisories/GHSA-mmg5-8x8q-v934'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
epss: 0.01975
epssPercentile: 0.79602
exploits:
  nuclei:
    - CVE-2026-61808
  checkedAt: '2026-09-24T07:53:11.043Z'
exploitAvailable: true
ingestedAt: '2026-09-09T21:22:45.524Z'
---

## Overview

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
