PT-2026-96826 · Lightrag · Lightrag
CVE-2026-85740
·
Published
2026-09-22
·
Updated
2026-09-28
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LightRAG versions prior to 1.5.5
Description
LightRAG contains a Server-Side Request Forgery (SSRF) issue in its native markdown parser. The
validated addresses() function in lightrag/parser/markdown/parser.py fails to consistently decode IPv6 transition wrappers that embed internal IPv4 addresses. An attacker who can upload a Markdown or textpack document can provide an external image URL using NAT64 (64:ff9b::/96), IPv4-compatible, or 6to4 wrappers. On deployments with compatible NAT64 or DNS64 routing, the download() and build guarded opener() functions may accept these wrappers and fetch internal resources, such as loopback services, RFC1918 internal hosts, or cloud instance metadata endpoints (e.g., 169.254.169.254), leading to the ingestion of sensitive internal data or IAM credentials.Recommendations
Update LightRAG to version 1.5.5.
As a temporary mitigation, restrict the use of the
NATIVE MD IMAGE DOWNLOAD ENABLED environment variable by setting it to False to disable native markdown image downloads.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightrag