CVE-2026-85734Critical· 9.1▾ MidnightLightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacker can submit password guesses at full request speed until a valid account password is found. Successful credential recovery grants authenticated access to documents, the knowledge graph, and administrative operations. This issue is fixed in version 1.5.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
lightrag-hku < 1.5.5Patched in:
lightrag-hku 1.5.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85709Medium· 5.3LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-85740High· 7.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-86062Medium· 6.1LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-77561Medium· 5.3Tinyauth is an authentication and authorization server
CVE-2026-92576High· 8.6HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses