lightrag-hku vulnerabilities
CVEs whose affected-version data names the lightrag-hku package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-61736Critical· 9.3PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
▾ Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
▾ Midnightlightrag-hku · lightrag-hkuEPSS 0.66%via GHSA
CVE-2026-39413Medium· 4.2lightrag-hku: JWT Algorithm Confusion Vulnerability
lightrag-hku: JWT Algorithm Confusion Vulnerability
▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.17%via OSV
CVE-2026-30762High· 7.5LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
▾ Twilightlightrag-hku · lightrag-hkuvia OSV
CVE-2025-6773Medium· 5.3HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.19%via OSV