PT-2026-96828 · Lightrag · Lightrag

CVE-2026-86062

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions LightRAG versions prior to 1.5.5
Description LightRAG WebUI is subject to stored cross-site scripting (XSS) because it renders assistant answer and thinking content as raw HTML without an HTML sanitizer. The application uses react-markdown configured with rehypeRaw and skipHtml=false, allowing an attacker to store raw HTML and JavaScript payloads by adding a document via the POST /documents/text or POST /documents/upload endpoints. When a user retrieves this content through the POST /query endpoint, the payload is rendered as active content in the browser.
Technical details include:
  • The vulnerable component is located in lightrag webui/src/components/retrieval/ChatMessage.tsx.
  • An attacker can use elements such as <iframe srcdoc="..."> to execute arbitrary JavaScript.
  • The Mermaid rendering path is also vulnerable because it is initialized with securityLevel: 'loose', which disables output sanitization and injects generated SVG via innerHTML.
  • KaTeX is configured with trust: true, which allows the loading of arbitrary external resources through includegraphics{URL}.
Successful exploitation allows the attacker to execute scripts in the LightRAG WebUI origin, enabling the theft of API tokens from localStorage and full API takeover.
Recommendations Update LightRAG to version 1.5.5. As a temporary mitigation, restrict the ability to upload or add documents via POST /documents/text and POST /documents/upload to trusted users only. Change the KaTeX configuration to trust: false to prevent arbitrary external resource loading.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86062
GHSA-XPJQ-3W4W-W5WR

Affected Products

Lightrag