{"schema_version":1,"title":"HKUDS LightRAG vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 8 vulnerabilities in HKUDS LightRAG: 5 in the last 7 days and 7 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86062, was published on 22 September 2026.","url":"https://junglewise.ai/threats/technologies/lightrag","json_url":"https://junglewise.ai/threats/technologies/lightrag.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/lightrag","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":8,"critical":3,"exploited":0,"last_7_days":5,"last_30_days":5,"last_90_days":7,"last_365_days":8},"latest":[{"cve":"CVE-2026-86062","cvss":6.1,"epss":0.0025,"slug":"cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx re","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.863+00:00","url":"https://junglewise.ai/threats/cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer"},{"cve":"CVE-2026-85740","cvss":7.1,"epss":0.0022,"slug":"cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:27.52+00:00","url":"https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-85725","cvss":5.9,"epss":0.0036,"slug":"cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plai","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.203+00:00","url":"https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability"},{"cve":"CVE-2026-85709","cvss":5.3,"epss":0.0039,"slug":"cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.02+00:00","url":"https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-39413","cvss":4.2,"epss":0.0021,"slug":"cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth","title":"HKUDS LightRAG JWT algorithm confusion in API auth","severity":"medium","exploited":false,"published_at":"2026-04-08T20:16:25.877+00:00","url":"https://junglewise.ai/threats/cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":2,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":5}],"related":[{"name":"HKUDS Nanobot","slug":"nanobot","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/nanobot"},{"name":"HKUDS OpenHarness","slug":"openharness","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/openharness"},{"name":"HKUDS Vibe-Trading","slug":"vibe-trading","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/vibe-trading"}],"technology":{"hub":true,"name":"HKUDS LightRAG","slug":"lightrag","vendor":{"name":"HKUDS","slug":"hkuds","url":"https://junglewise.ai/threats/vendors/hkuds"},"aliases":[],"category":"library","homepage":"https://github.com/HKUDS/LightRAG","repo_url":"https://github.com/HKUDS/LightRAG","description":"LightRAG is an open-source framework designed to enhance Retrieval-Augmented Generation (RAG) systems using graph-based structures.","url":"https://junglewise.ai/threats/technologies/lightrag"},"most_severe":[{"cve":"CVE-2026-61736","cvss":9.3,"epss":0.0142,"slug":"cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server","title":"HKUDS LightRAG permissive CORS policy in API server","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.217+00:00","url":"https://junglewise.ai/threats/cve-2026-61736-hkuds-lightrag-permissive-cors-policy-in-api-server"},{"cve":"CVE-2026-85734","cvss":9.1,"epss":0.0036,"slug":"cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.p","severity":"critical","exploited":false,"published_at":"2026-09-22T17:17:27.367+00:00","url":"https://junglewise.ai/threats/cve-2026-85734-lightrag-hku-login-endpoint-missing-rate-limiting-enables-brute"},{"cve":"CVE-2026-61740","cvss":4,"epss":0.0066,"slug":"cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode","title":"HKUDS LightRAG authentication bypass in API-key-only mode","severity":"critical","exploited":false,"published_at":"2026-07-15T15:16:48.35+00:00","url":"https://junglewise.ai/threats/cve-2026-61740-hkuds-lightrag-authentication-bypass-in-api-key-only-mode"},{"cve":"CVE-2026-85740","cvss":7.1,"epss":0.0022,"slug":"cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py","severity":"high","exploited":false,"published_at":"2026-09-22T17:17:27.52+00:00","url":"https://junglewise.ai/threats/cve-2026-85740-lightrag-ssrf-via-ipv6-transition-address-bypass-in-markdown"},{"cve":"CVE-2026-86062","cvss":6.1,"epss":0.0025,"slug":"cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx re","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.863+00:00","url":"https://junglewise.ai/threats/cve-2026-86062-lightrag-webui-stored-xss-in-chat-answer-renderer"},{"cve":"CVE-2026-85725","cvss":5.9,"epss":0.0036,"slug":"cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plai","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.203+00:00","url":"https://junglewise.ai/threats/cve-2026-85725-lightrag-plaintext-password-timing-attack-vulnerability"},{"cve":"CVE-2026-85709","cvss":5.3,"epss":0.0039,"slug":"cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses","title":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text","severity":"medium","exploited":false,"published_at":"2026-09-22T17:17:27.02+00:00","url":"https://junglewise.ai/threats/cve-2026-85709-lightrag-api-sensitive-information-exposure-in-error-responses"},{"cve":"CVE-2026-39413","cvss":4.2,"epss":0.0021,"slug":"cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth","title":"HKUDS LightRAG JWT algorithm confusion in API auth","severity":"medium","exploited":false,"published_at":"2026-04-08T20:16:25.877+00:00","url":"https://junglewise.ai/threats/cve-2026-39413-hkuds-lightrag-jwt-algorithm-confusion-in-api-auth"}],"generated_at":"2026-09-26T10:07:00.179841+00:00"}