PT-2026-96828 · Lightrag · Lightrag
CVE-2026-86062
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LightRAG versions prior to 1.5.5
Description
LightRAG WebUI is subject to stored cross-site scripting (XSS) because it renders assistant answer and thinking content as raw HTML without an HTML sanitizer. The application uses
react-markdown configured with rehypeRaw and skipHtml=false, allowing an attacker to store raw HTML and JavaScript payloads by adding a document via the POST /documents/text or POST /documents/upload endpoints. When a user retrieves this content through the POST /query endpoint, the payload is rendered as active content in the browser.Technical details include:
- The vulnerable component is located in
lightrag webui/src/components/retrieval/ChatMessage.tsx. - An attacker can use elements such as
<iframe srcdoc="...">to execute arbitrary JavaScript. - The Mermaid rendering path is also vulnerable because it is initialized with
securityLevel: 'loose', which disables output sanitization and injects generated SVG viainnerHTML. - KaTeX is configured with
trust: true, which allows the loading of arbitrary external resources throughincludegraphics{URL}.
Successful exploitation allows the attacker to execute scripts in the LightRAG WebUI origin, enabling the theft of API tokens from
localStorage and full API takeover.Recommendations
Update LightRAG to version 1.5.5.
As a temporary mitigation, restrict the ability to upload or add documents via
POST /documents/text and POST /documents/upload to trusted users only.
Change the KaTeX configuration to trust: false to prevent arbitrary external resource loading.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightrag