CVE-2026-61740 | HKUDS LightRAG up to 1.5.3 lightrag/api/auth.py combined_dependency X-API-Key improper authentication

SecurityVulns

A vulnerability was found in HKUDS LightRAG up to 1.5.3. It has been declared as critical. Affected by this vulnerability is the function combined_dependency of the file lightrag/api/auth.py. Such manipulation of the argument X-API-Key leads to improper authentication.

This vulnerability is referenced as CVE-2026-61740. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More