Critical severity9.1NVD Advisory· Published Sep 22, 2026· Updated Sep 22, 2026
CVE-2026-85734
CVE-2026-85734
Description
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication attempts. A network attacker can submit password guesses at full request speed until a valid account password is found. Successful credential recovery grants authenticated access to documents, the knowledge graph, and administrative operations. This issue is fixed in version 1.5.5.
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.