Skip to content

Known CVE

LightRAG <= 1.5.4 - Missing Authentication

LightRAG through version 1.5.4 contains a broken access control vulnerability caused by the API server binding to all network interfaces with authentication disabled, letting unauthenticated network attackers fully control indexed documents and resources, exploit requires network access.

CVE-2026-61808

High2026CVSS 7.5CWE-22

cve2026 · lightrag · lfi · traversal · ai

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website