Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-61808— LightRAG: Missing Authentication for Critical API Functions in Default Configuration

Quick assessment

Affected
HKUDS LightRAG
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Data Intelligence Lab@HKU LightRAG是Data Intelligence Lab@HKU大学的一个基于知识图谱的检索增强生成框架。 Data Intelligence Lab@HKU LightRAG 1.5.4及之前版本存在授权问题漏洞,该漏洞源于API服务器默认绑定所有网络接口且禁用身份验证,可能导致未经身份验证的网络攻击者读取索引文档内容、上传或删除文档、修改知识图谱、取消管道、清除缓存及消耗LLM资源。

CVSS 9.8 · Critical EPSS 2.50% · P84

Public Exploits 1

Affected Version Matrix 1

VendorProduct Version RangeStatus
HKUDS LightRAG < 1.5.5rc1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61808

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LightRAG: Missing Authentication for Critical API Functions in Default Configuration
Source: CVE Program / CVE List V5
Vulnerability Description
LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modify the knowledge graph, cancel pipelines, clear caches, and consume LLM resources. This issue is mitigated in version 1.5.5rc1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Data Intelligence Lab@HKU LightRAG 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Data Intelligence Lab@HKU LightRAG是Data Intelligence Lab@HKU大学的一个基于知识图谱的检索增强生成框架。 Data Intelligence Lab@HKU LightRAG 1.5.4及之前版本存在授权问题漏洞,该漏洞源于API服务器默认绑定所有网络接口且禁用身份验证,可能导致未经身份验证的网络攻击者读取索引文档内容、上传或删除文档、修改知识图谱、取消管道、清除缓存及消耗LLM资源。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
HKUDS LightRAG < 1.5.5rc1 -

II. Public POCs for CVE-2026-61808

# POC Description Source Link Shenlong Link
1 LightRAG through version 1.5.4 contains a broken access control vulnerability caused by the API server binding to all network interfaces with authentication disabled, letting unauthenticated network attackers fully control indexed documents and resources, exploit requires network access. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-61808.yaml POC Details
AI-Generated POC Premium
Qwen3.6-35B-A3B · 7366 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-61808

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-61808 (1)

Vendor Advisories for CVE-2026-61808 (1)

Same Patch Batch · HKUDS · 2026-08-07 · 5 CVEs total

CVE-2026-19243 6.3 MEDIUM HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection
CVE-2026-19246 6.3 MEDIUM HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url ser
CVE-2026-19244 4.7 MEDIUM HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control
CVE-2026-19245 3.3 LOW HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information discl

IV. Related Vulnerabilities

V. Comments for CVE-2026-61808

No comments yet


Leave a comment