Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses | Medium Risk 5.3 | 8 days ago | 1 hour ago |
|
|
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard | High Risk 7.1 | 8 days ago | 1 hour ago |
|
|
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks | Critical 9.1 | 8 days ago | 1 hour ago |
|
|
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection | Critical 9.5 | 2 months ago | 2 months ago |
|
|
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests | Critical 9.3 | 2 months ago | 2 months ago |
|
|
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests | Critical 9.3 | 2 months ago | 2 months ago |
|
|
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection | Unknown | 2 months ago | 2 months ago |
|
|
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass | High Risk 7.5 | 6 months ago | 2 months ago |
|
|
lightrag-hku: JWT Algorithm Confusion Vulnerability | Medium Risk 4.2 | 5 months ago | 2 months ago |
|
|
lightrag-hku: JWT Algorithm Confusion Vulnerability | Medium Risk 4.2 | 2 months ago | 2 months ago |
|
|
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass | High Risk 7.5 | 2 months ago | 2 months ago |
|
|
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir | Medium Risk 5.3 | 1 year ago | 2 months ago |
|
|
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir | Medium Risk 5.3 | 2 months ago | 2 months ago |
Page 1