A critical missing-authentication flaw tracked as CVE-2026-61808 affects LightRAG through version 1.5.4, leaving its API server exposed in the default configuration by binding to 0.0.0.0 with authentication disabled. The issue allows unauthenticated remote attackers to reach sensitive API functions over the network and perform actions including reading indexed document content, uploading or deleting documents, modifying the knowledge graph, canceling pipelines, clearing caches, and consuming LLM resources. The vulnerability is rated CVSS 9.8 and mapped to CWE-306.
LightRAG addressed the issue in 1.5.5rc1 with code, test, and documentation changes that add startup warnings when the service is bound to a non-loopback address without authentication and when WHITELIST_PATHS leaves /api/* routes publicly accessible. The patch also improves detection of wildcard whitelist entries such as /*, updates container examples and deployment guidance, and warns operators that Ollama-compatible endpoints can remain exposed unless access is restricted, such as limiting WHITELIST_PATHS to /health. Recommended mitigations are to upgrade, enable LIGHTRAG_API_KEY or AUTH_ACCOUNTS with TOKEN_SECRET, and restrict network access to the API server.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-61808 was published for a critical missing-authentication vulnerability affecting LightRAG through version 1.5.4, where the API server binds to all interfaces and lacks authentication by default. The CVE states remote attackers can read and manipulate data and operations, and notes mitigation in version 1.5.5rc1.
A LightRAG code change introduced startup warnings for non-loopback deployments without authentication, improved detection of WHITELIST_PATHS entries that leave Ollama-compatible /api routes exposed, and updated tests and documentation around the insecure default exposure. The change is referenced as the fix for GHSA-mmg5-8x8q-v934 and is described as mitigation rather than enforcing authentication by default.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.