logo

CVE-2026-61736: LightRAG Critical CORS Credential Bypass (CVSS 9.3)

ID: a134af0a-4ef9-5432-b442-ec115f655ed8

STIX ID: report--a134af0a-4ef9-5432-b442-ec115f655ed8

Feed Name: CosmicBytez Labs

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

...
...

A critical vulnerability (CVE-2026-61736, CVSS 9.3) was found in LightRAG where the default CORS configuration (CORS_ORIGINS="*" with allow_credentials=True) permits credentialed cross-origin requests from any origin. An attacker able to trick an authenticated user into visiting a malicious page can exfiltrate or modify knowledge graph data, query LLM backends with the victim's credentials, or fully compromise multi-tenant deployments; users are advised to upgrade to LightRAG 1.5.4 or explicitly restrict allowed origins and/or enforce network-level controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.