CVE-2026-85734
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/09/2026
Last modified:
22/09/2026
Description
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacker can submit password guesses at full request speed until a valid account password is found. Successful credential recovery grants authenticated access to documents, the knowledge graph, and administrative operations. This issue is fixed in version 1.5.5.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL


