PT-2026-96823 · Lightrag · Lightrag

CVE-2026-85709

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LightRAG versions prior to 1.5.5
Description The LightRAG API server returns raw Python exception text in HTTP error responses across multiple routers, including document routes.py, graph routes.py, query routes.py, ollama api.py, and lightrag server.py. This occurs when exceptions are caught and returned verbatim using patterns such as detail=str(e) or detail=str(exc).
This behavior can expose sensitive internal infrastructure details to network clients, such as server filesystem paths, database hostnames, ports, usernames, and database names. Additionally, it may leak language-model provider diagnostics, Python library internals, and configuration details. For backends configured via URIs, such as MongoDB, the connection string containing credentials may be disclosed. The risk is increased by the default unauthenticated configuration, which allows these responses to be accessed without credentials.
Recommendations Update to version 1.5.5. As a temporary mitigation, restrict network access to the API server to trusted clients only to prevent unauthorized triggering of error responses.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85709
GHSA-HRMJ-7RVJ-4HG8

Affected Products

Lightrag