PT-2026-96823 · Lightrag · Lightrag
CVE-2026-85709
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LightRAG versions prior to 1.5.5
Description
The LightRAG API server returns raw Python exception text in HTTP error responses across multiple routers, including
document routes.py, graph routes.py, query routes.py, ollama api.py, and lightrag server.py. This occurs when exceptions are caught and returned verbatim using patterns such as detail=str(e) or detail=str(exc).This behavior can expose sensitive internal infrastructure details to network clients, such as server filesystem paths, database hostnames, ports, usernames, and database names. Additionally, it may leak language-model provider diagnostics, Python library internals, and configuration details. For backends configured via URIs, such as MongoDB, the connection string containing credentials may be disclosed. The risk is increased by the default unauthenticated configuration, which allows these responses to be accessed without credentials.
Recommendations
Update to version 1.5.5.
As a temporary mitigation, restrict network access to the API server to trusted clients only to prevent unauthorized triggering of error responses.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightrag