PT-2026-96824 · Lightrag · Lightrag

CVE-2026-85725

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LightRAG versions prior to 1.5.5
Description When plaintext passwords are stored in AUTH ACCOUNTS, the verify password() function in lightrag/api/passwords.py uses the Python == operator for comparison. This operator is not constant-time and short-circuits upon encountering the first mismatched byte, creating response-time differences based on password length and matching prefixes. A network attacker with low-latency access can exploit this timing oracle by repeatedly querying the /login endpoint to recover the plaintext password character by character. Deployments using bcrypt-prefixed password values are not affected.
Recommendations Update to version 1.5.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85725
GHSA-C759-CX9P-MRWQ

Affected Products

Lightrag