Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
PyPI/lightrag-hku — 5 CVEs · VulnScope
pkg:PyPI/
lightrag-hku
5 total CVEs
CRITICAL
1
HIGH
2
MEDIUM
4
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.3
CVE-2026-61736
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
from 0, < 1.5.4
HIGH
7.5
CVE-2026-30762
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
from 0, < 1.4.13
HIGH
7.5
CVE-2026-30762
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
from 0, < 1.4.13
MEDIUM
5.3
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
from 0, < 1.3.8
MEDIUM
5.3
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
from 0, < 1.3.8
MEDIUM
4.2
lightrag-hku: JWT Algorithm Confusion Vulnerability
from 0, < 1.4.14
MEDIUM
4.2
lightrag-hku: JWT Algorithm Confusion Vulnerability
from 0, < 1.4.14
—
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
from 0, < 1.5.4
CVE-2025-6773
CVE-2025-6773
CVE-2026-39413
CVE-2026-39413
CVE-2026-61740