1.5.6
1 years ago
7 days ago
Known vulnerabilities in the lightrag-hku package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
lightrag-hku is a LightRAG: Simple and Fast Retrieval-Augmented Generation Affected versions of this package are vulnerable to Use of Hard-coded Credentials in the authentication process when a hardcoded default token secret is used and certain endpoints such as How to fix Use of Hard-coded Credentials? Upgrade | [,1.5.4) |
lightrag-hku is a LightRAG: Simple and Fast Retrieval-Augmented Generation Affected versions of this package are vulnerable to Permissive Cross-domain Policy with Untrusted Domains in the CORS configuration process. An attacker can gain unauthorized access to sensitive user data and perform actions on behalf of authenticated users by enticing a logged-in user to visit a malicious website, which then makes credentialed cross-origin requests to the server. How to fix Permissive Cross-domain Policy with Untrusted Domains? Upgrade | [,1.5.4) |
lightrag-hku is a LightRAG: Simple and Fast Retrieval-Augmented Generation Affected versions of this package are vulnerable to Improper Authentication via the file How to fix Improper Authentication? Upgrade | [,1.4.13) |
lightrag-hku is a LightRAG: Simple and Fast Retrieval-Augmented Generation Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature in the How to fix Improper Verification of Cryptographic Signature? Upgrade | [,1.4.14) |