PT-2026-96826 · Lightrag · Lightrag

CVE-2026-85740

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LightRAG versions prior to 1.5.5
Description LightRAG contains a Server-Side Request Forgery (SSRF) issue in its native markdown parser. The validated addresses() function in lightrag/parser/markdown/parser.py fails to consistently decode IPv6 transition wrappers that embed internal IPv4 addresses. An attacker who can upload a Markdown or textpack document can provide an external image URL using NAT64 (64:ff9b::/96), IPv4-compatible, or 6to4 wrappers. On deployments with compatible NAT64 or DNS64 routing, the download() and build guarded opener() functions may accept these wrappers and fetch internal resources, such as loopback services, RFC1918 internal hosts, or cloud instance metadata endpoints (e.g., 169.254.169.254), leading to the ingestion of sensitive internal data or IAM credentials.
Recommendations Update LightRAG to version 1.5.5. As a temporary mitigation, restrict the use of the NATIVE MD IMAGE DOWNLOAD ENABLED environment variable by setting it to False to disable native markdown image downloads.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85740
GHSA-VV3M-F8X4-7377

Affected Products

Lightrag