lightrag-hku has 5 CVEs on record between 2025 and 2026. 2 were published in the last 90 days. The median CVSS is 6.4 (medium), with 2 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 2 prev 2
5
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-61736Critical· 9.3LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests63CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection52CVE-2026-30762High· 7.5LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass41CVE-2025-6773Medium· 5.3HKUDS LightRAG allows Path Traversal via function upload_to_input_dir29CVE-2026-39413Medium· 4.2lightrag-hku: JWT Algorithm Confusion Vulnerability 23
lightrag-hku vulnerabilities
CVEs affecting lightrag-hku, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-61736Critical· 9.3PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
▾ Abyssallightrag-hku · lightrag-hkuEPSS 1.4%via GHSA
CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
▾ Midnightlightrag-hku · lightrag-hkuEPSS 0.66%via GHSA
CVE-2026-39413Medium· 4.2lightrag-hku: JWT Algorithm Confusion Vulnerability
lightrag-hku: JWT Algorithm Confusion Vulnerability
▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.17%via OSV
CVE-2026-30762High· 7.5LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
▾ Twilightlightrag-hku · lightrag-hkuvia OSV
CVE-2025-6773Medium· 5.3HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.19%via OSV