Data Intelligence Lab@HKU LightRAG是Data Intelligence Lab@HKU大学的一个基于知识图谱的检索增强生成框架。 Data Intelligence Lab@HKU LightRAG 1.5.4及之前版本存在授权问题漏洞,该漏洞源于API服务器默认绑定所有网络接口且禁用身份验证,可能导致未经身份验证的网络攻击者读取索引文档内容、上传或删除文档、修改知识图谱、取消管道、清除缓存及消耗LLM资源。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | LightRAG through version 1.5.4 contains a broken access control vulnerability caused by the API server binding to all network interfaces with authentication disabled, letting unauthenticated network attackers fully control indexed documents and resources, exploit requires network access. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-61808.yaml | POC Details |
| CVE-2026-19243 | 6.3 MEDIUM | HKUDS nanobot Shell Allowlist shell.py ExecTool._spawn os command injection |
| CVE-2026-19246 | 6.3 MEDIUM | HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url ser |
| CVE-2026-19244 | 4.7 MEDIUM | HKUDS nanobot MCP enabledTools Scope mcp.py connect_mcp_servers access control |
| CVE-2026-19245 | 3.3 LOW | HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information discl |
No comments yet