{"data":{"id":"05556d9c-4841-4236-9268-4633e14e93a5","title":"CVE-2026-85709: LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py","summary":"LightRAG is a tool for RAG (retrieval-augmented generation, where an AI pulls in external documents to answer questions). Before version 1.5.5, when errors occurred, the API server exposed sensitive information like server file paths, database details, and credentials in error messages that anyone could read without logging in.","solution":"Update to version 1.5.5, where this issue is fixed.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85709","publishedAt":"2026-09-22T17:17:27.020Z","cveId":"CVE-2026-85709","cweIds":["CWE-209"],"cvssScore":"5.3","cvssSeverity":"medium","severity":"medium","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["LightRAG"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-22T17:17:27.020Z","capecIds":["CAPEC-54"],"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}