HTML Injection Vulnerability in LightRAG WebUI Affecting LightRAG
CVE-2026-86062
6.1MEDIUM
What is CVE-2026-86062?
The LightRAG WebUI prior to version 1.5.5 is vulnerable to an HTML injection issue that allows an attacker to store unvalidated HTML content. This content can execute attacker-controlled JavaScript, including scripts that may interact with local storage or perform API actions on behalf of the user. The vulnerability arises from the usage of react-markdown and rehypeRaw without an adequate HTML sanitizer, exposing users to potential exploitation through rendered content.
Affected Version(s)
LightRAG < 1.5.5
