{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/lightrag-hku--1.5.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lightrag-hku:lightrag-hku:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-85734"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lightrag-hku (\u003c 1.5.5)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","authentication","web-application"],"_cs_type":"threat","_cs_vendors":["LightRAG-HKU"],"content_html":"\u003cp\u003eLightRAG-HKU, a framework for knowledge graph retrieval, contains a critical security flaw in its authentication mechanism. The application's \u003ccode\u003e/login\u003c/code\u003e endpoint, implemented in \u003ccode\u003elightrag/api/lightrag_server.py\u003c/code\u003e, fails to implement rate limiting, account lockout, or request delays for failed authentication attempts. This oversight allows an unauthenticated, network-reachable attacker to programmatically iterate through password lists at full network speed to compromise administrative or user accounts. The vulnerability, tracked as CVE-2026-85734, affects all versions prior to 1.5.5. Given the sensitivity of the data stored within LightRAG knowledge graphs, successful exploitation provides unauthorized access to proprietary documents and administrative operations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable instances of LightRAG-HKU on default port 9621.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the target HTTP service to confirm the presence of the \u003ccode\u003e/login\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a dictionary of common passwords or credential lists for brute-force operations.\u003c/li\u003e\n\u003cli\u003eAttacker writes a script to automate HTTP POST requests to the \u003ccode\u003e/login\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker executes the script, passing user credentials via \u003ccode\u003eform_data\u003c/code\u003e without encountering server-side throttling.\u003c/li\u003e\n\u003cli\u003eAttacker monitors the HTTP response codes (e.g., waiting for a 200 OK) to identify successful password matches.\u003c/li\u003e\n\u003cli\u003eAttacker uses the compromised credentials to access the LightRAG API and extract sensitive knowledge graph information.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full unauthorized access to the LightRAG instance. Depending on the deployment, this could lead to the exposure of confidential knowledge stored in the graph, unauthorized administrative changes, and full exfiltration of sensitive data processed by the application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate LightRAG-HKU to version 1.5.5 or later immediately to patch CVE-2026-85734.\u003c/li\u003e\n\u003cli\u003eImplement external rate limiting or a Web Application Firewall (WAF) in front of the LightRAG-HKU service to detect and block high-frequency POST requests to the \u003ccode\u003e/login\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous patterns of 401 Unauthorized status codes from single IP addresses directed at the \u003ccode\u003e/login\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T01:54:20Z","date_published":"2026-09-23T01:54:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-lightrag-login-brute-force/","summary":"The /login endpoint in LightRAG-HKU versions prior to 1.5.5 lacks rate limiting or account lockout, enabling high-speed credential brute-force attacks.","title":"Unauthenticated Brute-Force Vulnerability in LightRAG-HKU","url":"https://feed.craftedsignal.io/briefs/2026-09-lightrag-login-brute-force/"}],"language":"en","title":"CraftedSignal Threat Feed - Lightrag-Hku (\u003c 1.5.5)","version":"https://jsonfeed.org/version/1.1"}