Back to CVE List

CVE-2026-39413

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
4.2 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N

Vulnerability Description

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.4.14, the LightRAG API is vulnerable to a JWT algorithm confusion attack where an attacker can forge tokens by specifying 'alg': 'none' in the JWT header. Since the jwt.decode() call does not explicitly deny the 'none' algorithm, a crafted token without a signature will be accepted as valid, leading to unauthorized access. This vulnerability is fixed in 1.4.14.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-347
Source
GitHub
Vendor
pip
Product
lightrag-hku

External References

Discussion (0)

Add Comment

No comments yet. Be the first!