PT-2026-69135 · Lightrag · Lightrag

CVE-2026-61808

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LightRAG versions prior to 1.5.5rc1
Description The API server binds to all network interfaces with authentication disabled by default. This allows an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources.
Recommendations Update to version 1.5.5rc1.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61808
GHSA-MMG5-8X8Q-V934

Affected Products

Lightrag