CVE-2026-85709: LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py
Summary
LightRAG is a tool for RAG (retrieval-augmented generation, where an AI pulls in external documents to answer questions). Before version 1.5.5, when errors occurred, the API server exposed sensitive information like server file paths, database details, and credentials in error messages that anyone could read without logging in.
Solution / Mitigation
Update to version 1.5.5, where this issue is fixed.
Vulnerability Details
5.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
network
low
none
none
September 22, 2026
Classification
Affected Vendors
Related Issues
GHSA-382c-vx95-w3p5: Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-85709
First tracked: September 22, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 92%