CVE Explorer
CVE-2026-61736
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing destructive actions such
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"LightRAG","vendor":"HKUDS","versions":[{"status":"affected","version":"< 1.5.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":9.3,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"CHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-942","description":"CWE-942: Permissive Cross-domain Policy with Untrusted Domains","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/problemTypes/0/descriptions/0
Source references
7 source assertions{"name":"https://github.com/HKUDS/LightRAG/commit/09567a4c983f580050db63569dd477122c058c3d","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/LightRAG/commit/09567a4c983f580050db63569dd477122c058c3d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/2
{"name":"https://github.com/HKUDS/LightRAG/commit/df68d75f9dc29dd340ffb6794b48f48c4fdc9a2d","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/LightRAG/commit/df68d75f9dc29dd340ffb6794b48f48c4fdc9a2d"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/3
{"name":"https://github.com/HKUDS/LightRAG/commit/ebba6548639c0f2e8919100eff76b401f1222252","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/LightRAG/commit/ebba6548639c0f2e8919100eff76b401f1222252"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/4
{"name":"https://github.com/HKUDS/LightRAG/pull/3317","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/LightRAG/pull/3317"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/1
{"name":"https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4","tags":["x_refsource_MISC"],"url":"https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/5
{"tags":["exploit"],"url":"https://github.com/HKUDS/LightRAG/security/advisories/GHSA-6x6h-qqr7-855w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/adp/0/references/0
{"name":"https://github.com/HKUDS/LightRAG/security/advisories/GHSA-6x6h-qqr7-855w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/HKUDS/LightRAG/security/advisories/GHSA-6x6h-qqr7-855w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:03c287a91a9d92b8a183da9a0a5e1ce18cfa5ffb73b70b6fb942d333acb280e9 · sha256:075b5ca8421ea00f… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.