Known Vulnerabilities for Lightrag by Hkuds
Listed below are 1 of the newest known vulnerabilities associated with "Lightrag" by "Hkuds".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86062 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/Cha... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-85740 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/mar... | Not Provided | 2026-09-22 | 2026-09-28 |
| CVE-2026-85734 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/li... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-85725 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.p... | Not Provided | 2026-09-22 | 2026-09-25 |
| CVE-2026-85709 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python ... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-61808 json | LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all... | Not Provided | 2026-08-07 | 2026-08-10 |
| CVE-2026-61740 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-61736 json | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combi... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-39413 json | Not Provided | 2026-04-08 | 2026-07-24 |