{"data":{"id":"4d1f032d-ce6f-4518-870c-6dfa46defa3e","title":"GHSA-xpjq-3w4w-w5wr: lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content","summary":"LightRAG WebUI has a stored cross-site scripting (XSS) vulnerability where it renders chat answers as raw HTML without sanitization, allowing an attacker to inject malicious JavaScript through uploaded documents that executes when other users view the response. Because answer content comes from user-uploaded files and is rendered with `rehypeRaw` plugin enabled and no HTML sanitizer, an attacker can steal authentication tokens and take over the API.","solution":"The source text does not explicitly describe a fix, patch, or version update. It recommends adding `rehype-sanitize` with an allow-list and a custom `urlTransform`, disabling mermaid's `securityLevel: 'loose'` setting, and setting KaTeX's `trust: false`, but these are suggestions rather than confirmed mitigations in the source. N/A -- no explicit mitigation or patched version is mentioned in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-xpjq-3w4w-w5wr","publishedAt":"2026-09-22T20:40:27.000Z","cveId":"CVE-2026-86062","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["rag_poisoning"],"issueType":"vulnerability","affectedPackages":["lightrag-hku@<= 1.5.4 (fixed: 1.5.5)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["LightRAG","LangChain"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-09-22T20:40:27.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}