Critical severityNVD Advisory· Published Jul 15, 2026· Updated Jul 15, 2026
LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
CVE-2026-61740
Description
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET, /auth-status and /login can mint guest JWTs, and combined_dependency in lightrag/api/utils_api.py accepts a valid guest token before checking the API key. A remote unauthenticated attacker can call endpoints guarded by combined_auth, including document read, upload, deletion, graph mutation, and query endpoints. This vulnerability is fixed in 1.5.4.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lightrag-hkuPyPI | < 1.5.4 | 1.5.4 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-f4vv-55c2-5789ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-61740ghsaADVISORY
- github.com/HKUDS/LightRAG/commit/f7819aa3a49a9d8d92eed8251d82d6ebcafa8cbaghsax_refsource_MISCWEB
- github.com/HKUDS/LightRAG/pull/3319ghsax_refsource_MISCWEB
- github.com/HKUDS/LightRAG/releases/tag/v1.5.4ghsax_refsource_MISCWEB
- github.com/HKUDS/LightRAG/security/advisories/GHSA-f4vv-55c2-5789ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.