CVE-2026-61736: LightRAG Critical CORS Credential Bypass (CVSS 9.3)
ID: a134af0a-4ef9-5432-b442-ec115f655ed8
STIX ID: report--a134af0a-4ef9-5432-b442-ec115f655ed8
Feed Name: CosmicBytez Labs
A critical vulnerability (CVE-2026-61736, CVSS 9.3) was found in LightRAG where the default CORS configuration (CORS_ORIGINS="*" with allow_credentials=True) permits credentialed cross-origin requests from any origin. An attacker able to trick an authenticated user into visiting a malicious page can exfiltrate or modify knowledge graph data, query LLM backends with the victim's credentials, or fully compromise multi-tenant deployments; users are advised to upgrade to LightRAG 1.5.4 or explicitly restrict allowed origins and/or enforce network-level controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
