{"id":"CVE-2026-61740","aliases":["GHSA-f4vv-55c2-5789","PYSEC-2026-3475"],"url":"https://o3.security/vulnerability/CVE-2026-61740","summary":"LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection","details":"LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET, /auth-status and /login can mint guest JWTs, and combined_dependency in lightrag/api/utils_api.py accepts a valid guest token before checking the API key. A remote unauthenticated attacker can call endpoints guarded by combined_auth, including document read, upload, deletion, graph mutation, and query endpoints. This vulnerability is fixed in 1.5.4.","published":"2026-07-15T14:14:41.064Z","modified":"2026-08-12T03:51:21.744436194Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"lightrag-hku","fixedVersion":"1.5.4"}],"fix":{"url":"https://github.com/HKUDS/LightRAG/commit/f7819aa3a49a9d8d92eed8251d82d6ebcafa8cba","label":"HKUDS/LightRAG@f7819aa"},"references":[{"type":"WEB","url":"https://github.com/HKUDS/LightRAG/releases/tag/v1.5.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61740.json"},{"type":"ADVISORY","url":"https://github.com/HKUDS/LightRAG/security/advisories/GHSA-f4vv-55c2-5789"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61740"},{"type":"FIX","url":"https://github.com/HKUDS/LightRAG/commit/f7819aa3a49a9d8d92eed8251d82d6ebcafa8cba"},{"type":"FIX","url":"https://github.com/HKUDS/LightRAG/pull/3319"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.744436194Z"}}