CVE-2026-61736
CVE-2026-61736 is a critical-severity vulnerability with a CVSS 3.x base score of 9.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-942.
Key facts
- Severity: Critical (CVSS 3.x base score 9.3)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-942
- Published:
- Last modified:
Description
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing destructive actions such as deleting the document store. This vulnerability is fixed in 1.5.4.
Frequently asked questions
- What is CVE-2026-61736?
- LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for credentialed cross-origin requests. Any malicious website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating documents and knowledge graph data or performing destructive actions such as deleting the document store. This vulnerability is fixed in 1.5.4.
- How severe is CVE-2026-61736?
- CVE-2026-61736 has a CVSS 3.x base score of 9.3, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2026-61736 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-61736?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-61736 published?
- CVE-2026-61736 was published on 2026-07-15.
References
- https://github.com/HKUDS/LightRAG/commit/09567a4c983f580050db63569dd477122c058c3d
- https://github.com/HKUDS/LightRAG/commit/df68d75f9dc29dd340ffb6794b48f48c4fdc9a2d
- https://github.com/HKUDS/LightRAG/commit/ebba6548639c0f2e8919100eff76b401f1222252
- https://github.com/HKUDS/LightRAG/pull/3317
- https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4
- https://github.com/HKUDS/LightRAG/security/advisories/GHSA-6x6h-qqr7-855w
Other CWE-942 vulnerabilities
- CVE-2022-26969 — Critical (CVSS 9.8): In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
- CVE-2022-31736 — Critical (CVSS 9.8): A malicious website could have learned the size of a cross-origin resource that supported Range requests. This…
- CVE-2026-34449 — Critical (CVSS 9.6): SiYuan is a personal knowledge management system. Prior to version 3.6.2, a malicious website can achieve Remote Code…
- CVE-2026-30924 — Critical (CVSS 9.6): qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that…
- CVE-2026-9739 — Critical (CVSS 9.4): Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented…
- CVE-2026-8948 — Critical (CVSS 9.1): Same-origin policy bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 151 and Thunderbird…