HTML Injection Vulnerability in LightRAG WebUI Affecting LightRAG
CVE-2026-86062

6.1MEDIUM

Key Information:

Vendor

Hkuds

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-86062?

The LightRAG WebUI prior to version 1.5.5 is vulnerable to an HTML injection issue that allows an attacker to store unvalidated HTML content. This content can execute attacker-controlled JavaScript, including scripts that may interact with local storage or perform API actions on behalf of the user. The vulnerability arises from the usage of react-markdown and rehypeRaw without an adequate HTML sanitizer, exposing users to potential exploitation through rendered content.

Affected Version(s)

LightRAG < 1.5.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.