PT-2026-96824 · Lightrag · Lightrag
CVE-2026-85725
·
Published
2026-09-22
·
Updated
2026-09-23
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
LightRAG versions prior to 1.5.5
Description
When plaintext passwords are stored in
AUTH ACCOUNTS, the verify password() function in lightrag/api/passwords.py uses the Python == operator for comparison. This operator is not constant-time and short-circuits upon encountering the first mismatched byte, creating response-time differences based on password length and matching prefixes. A network attacker with low-latency access can exploit this timing oracle by repeatedly querying the /login endpoint to recover the plaintext password character by character. Deployments using bcrypt-prefixed password values are not affected.Recommendations
Update to version 1.5.5.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightrag