CVE-2026-61808: LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an...

Added to the CISA Known Exploited Vulnerabilities catalog on 07 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 9.8.

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or delete documents, modi...

Required action: Review and patch if applicable to your AI infrastructure.