Vulnerability in LightRAG Affects MarkDown Parsing and Image URL Handling
CVE-2026-85740

7.1HIGH

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-85740?

LightRAG, prior to version 1.5.5, contains a vulnerability in its markdown parser where the function _validated_addresses improperly evaluates IPv4 addresses within IPv6 transition wrappers. This allows attackers to supply image URLs that exploit NAT64 or DNS64 routing, leading to the unintended fetching of internal resources. Although the current interpreter blocks certain address forms, the fix implemented in version 1.5.5 ensures more restrictive handling of all documented address wrappers, enhancing overall security.

Affected Version(s)

LightRAG < 1.5.5

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.