Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
lightrag-hku lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses Medium Risk 5.3 8 days ago 1 hour ago
lightrag-hku lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard High Risk 7.1 8 days ago 1 hour ago
lightrag-hku lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks Critical 9.1 8 days ago 1 hour ago
lightrag-hku LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection Critical 9.5 2 months ago 2 months ago
lightrag-hku LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests Critical 9.3 2 months ago 2 months ago
lightrag-hku LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests Critical 9.3 2 months ago 2 months ago
lightrag-hku LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection Unknown 2 months ago 2 months ago
lightrag-hku LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass High Risk 7.5 6 months ago 2 months ago
lightrag-hku lightrag-hku: JWT Algorithm Confusion Vulnerability Medium Risk 4.2 5 months ago 2 months ago
lightrag-hku lightrag-hku: JWT Algorithm Confusion Vulnerability Medium Risk 4.2 2 months ago 2 months ago
lightrag-hku LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass High Risk 7.5 2 months ago 2 months ago
lightrag-hku HKUDS LightRAG allows Path Traversal via function upload_to_input_dir Medium Risk 5.3 1 year ago 2 months ago
lightrag-hku HKUDS LightRAG allows Path Traversal via function upload_to_input_dir Medium Risk 5.3 2 months ago 2 months ago