CVE-2026-61736 | HKUDS LightRAG up to 1.5.3 CORS lightrag_server.py CORS_ORIGINS/allow_credentials cross-domain policy
A vulnerability identified as problematic has been detected in HKUDS LightRAG up to 1.5.3. This vulnerability affects unknown code of the file lightrag/api/lightrag_server.py of the component CORS. The manipulation of the argument CORS_ORIGINS/allow_credentials leads to permissive cross-domain policy with untrusted domains.
This vulnerability is listed as CVE-2026-61736. The attack may be initiated remotely. There is no available exploit.VulDB Recent EntriesRead More