LightRAG versions prior to 1.4.14 contain a JWT algorithm confusion vulnerability that allows attackers to forge authentication tokens by specifying 'alg': 'none' in the JWT header. The vulnerable jwt.decode() implementation fails to explicitly reject the none algorithm, permitting unsigned tokens to be accepted as valid and enabling unauthorized API access. The vulnerability presents a medium severity risk (CVSS 6.5) requiring low attack complexity and network accessibility, though it does require prior authentication (PR:L). The primary impact is confidentiality compromise through unauthorized access to sensitive data, with no impact to integrity or availability. The attack vector is network-based and does not require user interaction. There is no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.00016 indicating minimal real-world exploitation risk. The vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog and shows no community activity on exploit tracking platforms. Organizations running LightRAG should prioritize upgrading to version 1.4.14 to remediate this authentication bypass risk, particularly if the service is exposed to authenticated users with potential malicious intent.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.14CPE matchmatch criteria | cpe:2.3:a:hkuds:lightrag:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.