Vulnerability in LightRAG Affects MarkDown Parsing and Image URL Handling
CVE-2026-85740
7.1HIGH
What is CVE-2026-85740?
LightRAG, prior to version 1.5.5, contains a vulnerability in its markdown parser where the function _validated_addresses improperly evaluates IPv4 addresses within IPv6 transition wrappers. This allows attackers to supply image URLs that exploit NAT64 or DNS64 routing, leading to the unintended fetching of internal resources. Although the current interpreter blocks certain address forms, the fix implemented in version 1.5.5 ensures more restrictive handling of all documented address wrappers, enhancing overall security.
Affected Version(s)
LightRAG < 1.5.5
