{"schema_version":1,"title":"lightrag-hku (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in lightrag-hku (PyPI): 5 in the last 7 days and 9 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86062, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/lightrag-hku","json_url":"https://junglewise.ai/threats/technologies/lightrag-hku.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/lightrag-hku","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":10,"critical":3,"exploited":0,"last_7_days":5,"last_30_days":5,"last_90_days":9,"last_365_days":10},"latest":[{"cve":"CVE-2026-86062","cvss":6.1,"epss":0.0025,"slug":"cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx re","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.863+00:00","url":"https://junglewise.ai/threats/cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer"},{"cve":"CVE-2026-85740","cvss":7.1,"epss":0.0022,"slug":"cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:27.52+00:00","url":"https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-85725","cvss":5.9,"epss":0.0036,"slug":"cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plai","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.203+00:00","url":"https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability"},{"cve":"CVE-2026-85709","cvss":5.3,"epss":0.0039,"slug":"cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.02+00:00","url":"https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-30762","cvss":3.1,"slug":"cve-2026-30762-lightrag-hardcoded-jwt-signing-secret-allows-authentication","title":"PYSEC-2026-2593 - LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:47.91597+00:00","url":"https://junglewise.ai/threats/cve-2026-30762-lightrag-hardcoded-jwt-signing-secret-allows-authentication"},{"cve":"CVE-2025-6773","cvss":3.1,"epss":0.0019,"slug":"cve-2025-6773-hkuds-lightrag-allows-path-traversal-via-function-upload-to-input","title":"PYSEC-2026-1539 - HKUDS LightRAG allows Path Traversal via function upload_to_input_dir","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.887572+00:00","url":"https://junglewise.ai/threats/cve-2025-6773-hkuds-lightrag-allows-path-traversal-via-function-upload-to-input"},{"cve":"CVE-2026-39413","cvss":4.2,"epss":0.0021,"slug":"cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth","title":"HKUDS LightRAG JWT algorithm confusion in API auth","severity":"medium","exploited":false,"published_at":"2026-04-08T20:16:25.877+00:00","url":"https://junglewise.ai/threats/cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":2,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":5}],"related":[{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":156,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"picklescan (PyPI)","slug":"picklescan","vulnerabilities":74,"url":"https://junglewise.ai/threats/technologies/picklescan"},{"name":"openbabel (PyPI)","slug":"openbabel","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/openbabel"},{"name":"apache-superset (PyPI)","slug":"apache-superset","vulnerabilities":44,"url":"https://junglewise.ai/threats/technologies/apache-superset"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":37,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":34,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"weblate (PyPI)","slug":"weblate","vulnerabilities":33,"url":"https://junglewise.ai/threats/technologies/weblate"},{"name":"mcp-atlassian (PyPI)","slug":"mcp-atlassian","vulnerabilities":30,"url":"https://junglewise.ai/threats/technologies/mcp-atlassian"},{"name":"crawl4ai (PyPI)","slug":"crawl4ai","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/crawl4ai"},{"name":"moin (PyPI)","slug":"moin","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/moin"}],"technology":{"hub":true,"name":"lightrag-hku (PyPI)","slug":"lightrag-hku","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://pypi.org/project/lightrag-hku/","repo_url":"https://github.com/HKU-Smart-OT/LightRAG","description":"lightrag-hku is a Python package implementing a modular retrieval-augmented generation framework.","url":"https://junglewise.ai/threats/technologies/lightrag-hku"},"most_severe":[{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-85740","cvss":7.1,"epss":0.0022,"slug":"cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:27.52+00:00","url":"https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown"},{"cve":"CVE-2026-86062","cvss":6.1,"epss":0.0025,"slug":"cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx re","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.863+00:00","url":"https://junglewise.ai/threats/cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer"},{"cve":"CVE-2026-85725","cvss":5.9,"epss":0.0036,"slug":"cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plai","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.203+00:00","url":"https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability"},{"cve":"CVE-2026-85709","cvss":5.3,"epss":0.0039,"slug":"cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.02+00:00","url":"https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses"},{"cve":"CVE-2026-39413","cvss":4.2,"epss":0.0021,"slug":"cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth","title":"HKUDS LightRAG JWT algorithm confusion in API auth","severity":"medium","exploited":false,"published_at":"2026-04-08T20:16:25.877+00:00","url":"https://junglewise.ai/threats/cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth"},{"cve":"CVE-2025-6773","cvss":3.1,"epss":0.0019,"slug":"cve-2025-6773-hkuds-lightrag-allows-path-traversal-via-function-upload-to-input","title":"PYSEC-2026-1539 - HKUDS LightRAG allows Path Traversal via function upload_to_input_dir","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.887572+00:00","url":"https://junglewise.ai/threats/cve-2025-6773-hkuds-lightrag-allows-path-traversal-via-function-upload-to-input"},{"cve":"CVE-2026-30762","cvss":3.1,"slug":"cve-2026-30762-lightrag-hardcoded-jwt-signing-secret-allows-authentication","title":"PYSEC-2026-2593 - LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:47.91597+00:00","url":"https://junglewise.ai/threats/cve-2026-30762-lightrag-hardcoded-jwt-signing-secret-allows-authentication"}],"generated_at":"2026-09-26T13:07:00.120236+00:00"}