lightragGHSA-v9w6-9hq9-33ch
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
Medium5.3CVE-2025-6773 · Published Jun 27, 2025 · updated Jul 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| lightrag-hku PyPI | < 1.3.8 | 1.3.8 |
Details and references
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of the file lightrag/api/routers/document_routes.py of the component File Upload. The manipulation of the argument file.filename leads to path traversal. It is possible to launch the attack on the local host. The identifier of the patch is 60777d535b719631680bcf5d0969bdef79ca4eaf. It is recommended to apply a patch to fix this issue.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22
- Also known as
- CVE-2025-6773, PYSEC-2026-1539
- nvd.nist.gov/vuln/detail/CVE-2025-6773
- github.com/HKUDS/LightRAG/issues/1692
- github.com/HKUDS/LightRAG/issues/1692#issuecomment-3009368235
- github.com/HKUDS/LightRAG/commit/60777d535b719631680bcf5d0969bdef79ca4eaf
- github.com/HKUDS/LightRAG
- vuldb.com/?ctiid.314089
- vuldb.com/?id.314089
- vuldb.com/?submit.601276
More lightrag advisories
All| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 4 | LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass CVE-2026-30762High7.5fixed in 1.4.13 | High7.5 | 1.4.13 |
| Apr 8 | lightrag-hku: JWT Algorithm Confusion Vulnerability CVE-2026-39413Medium4.2fixed in 1.4.14 | Medium4.2 | 1.4.14 |
| Jul 20 | LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests CVE-2026-61736Critical9.3fixed in 1.5.4 | Critical9.3 | 1.5.4 |
| Jul 20 | LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection CVE-2026-61740Criticalfixed in 1.5.4 | Critical | 1.5.4 |
| Sep 22 | lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses CVE-2026-85709Medium5.3fixed in 1.5.5 | Medium5.3 | 1.5.5 |
| Sep 22 | lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function CVE-2026-85725Medium5.9fixed in 1.5.5 | Medium5.9 | 1.5.5 |