Agents
LightRAG gets seven advisories in one day, including SSRF through IPv6-transition addresses and XSS from ingested content
On 22 September GitHub published seven lightrag-hku advisories. They include an SSRF-guard bypass through NAT64, 6to4 and IPv4-compatible addresses in the image downloader (CVE-2026-85740), stored XSS in the chat renderer from ingested documents (CVE-2026-86062), and a critical missing rate limit on /login (CVE-2026-85734). The same IPv6-transition bypass hit Cloudreve that day, so any agent or RAG fetch allowlist should be checked for it.
↳ Follow the thread