15 Total advisories
15 Vulnerabilities
0 Malware
Dependency scanning
Check whether lightrag-hku is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.1
CVE-2026-85740
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
MEDIUM 6.1
CVE-2026-86062
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
MEDIUM 5.3
CVE-2026-85709
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
MEDIUM 5.9
CVE-2026-85725
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
CRITICAL 9.1
CVE-2026-85734
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
UNKNOWN
CVE-2026-61740
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CRITICAL 9.3
CVE-2026-61736
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
UNKNOWN
CVE-2026-61740
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CRITICAL 9.3
CVE-2026-61736
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
HIGH 7.5
CVE-2026-30762
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
MEDIUM 4.2
CVE-2026-39413
lightrag-hku: JWT Algorithm Confusion Vulnerability
HIGH 7.5
CVE-2026-30762
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass
MEDIUM 4.2
CVE-2026-39413
lightrag-hku: JWT Algorithm Confusion Vulnerability
MEDIUM 5.3
CVE-2025-6773
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
MEDIUM 5.3
CVE-2025-6773
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes