CVE-2026-85709: CWE-209: Generation of Error Message Containing Sensitive Information in HKUDS LightRAG
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equivalent formatted-message paths expose server filesystem paths, database host, port, user, and database names, language-model provider diagnostics, configuration details, and Python library internals to a network client that can trigger an error. The default unauthenticated configuration makes those responses reachable without credentials, and URI-configured backends can disclose connection strings containing credentials depending on the underlying driver error. This issue is fixed in version 1.5.5.
AI Analysis
Technical Summary
LightRAG versions before 1.5.5 have a CWE-209 vulnerability where error handlers in multiple server-side Python modules return detailed exception messages to clients. These messages disclose sensitive internal information such as filesystem paths, database connection strings (potentially including credentials), language model provider diagnostics, and configuration details. Because the default setup does not require authentication, any network client can provoke errors and obtain this sensitive information. The vulnerability is fixed in version 1.5.5.
Potential Impact
An unauthenticated remote attacker can trigger errors on the LightRAG API server and receive detailed error messages that leak sensitive information including server filesystem paths, database host, port, user, database names, configuration details, and internal diagnostics. This information disclosure could aid attackers in further reconnaissance or targeted attacks. There is no indication of direct integrity or availability impact.
Mitigation Recommendations
Upgrade LightRAG to version 1.5.5 or later, where this issue is fixed. Until then, consider restricting access to the API server to trusted clients to reduce exposure. Patch status is confirmed fixed in version 1.5.5.
CVE-2026-85709: CWE-209: Generation of Error Message Containing Sensitive Information in HKUDS LightRAG
Description
LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and lightrag_server.py. The detail=str(e), detail=str(exc), and equivalent formatted-message paths expose server filesystem paths, database host, port, user, and database names, language-model provider diagnostics, configuration details, and Python library internals to a network client that can trigger an error. The default unauthenticated configuration makes those responses reachable without credentials, and URI-configured backends can disclose connection strings containing credentials depending on the underlying driver error. This issue is fixed in version 1.5.5.
CVSS v3.1
Score 5.3medium
Affected software
HKUDS
LightRAG
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
LightRAG versions before 1.5.5 have a CWE-209 vulnerability where error handlers in multiple server-side Python modules return detailed exception messages to clients. These messages disclose sensitive internal information such as filesystem paths, database connection strings (potentially including credentials), language model provider diagnostics, and configuration details. Because the default setup does not require authentication, any network client can provoke errors and obtain this sensitive information. The vulnerability is fixed in version 1.5.5.
Potential Impact
An unauthenticated remote attacker can trigger errors on the LightRAG API server and receive detailed error messages that leak sensitive information including server filesystem paths, database host, port, user, database names, configuration details, and internal diagnostics. This information disclosure could aid attackers in further reconnaissance or targeted attacks. There is no indication of direct integrity or availability impact.
Mitigation Recommendations
Upgrade LightRAG to version 1.5.5 or later, where this issue is fixed. Until then, consider restricting access to the API server to trusted clients to reduce exposure. Patch status is confirmed fixed in version 1.5.5.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-04T14:45:10.647Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2add8f7a7c541066e1174
Added to database: 09/22/2026, 16:33:28 UTC
Last enriched: 09/22/2026, 16:48:00 UTC
Last updated: 09/23/2026, 01:58:06 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.