HKUDS LightRAG File Upload document_routes.py upload_to_input_dir path traversal
Vulnerability Description
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function upload_to_input_dir of the file lightrag/api/routers/document_routes.py of the component File Upload. The manipulation of the argument file.filename leads to path traversal. It is possible to launch the attack on the local host. The identifier of the patch is 60777d535b719631680bcf5d0969bdef79ca4eaf. It is recommended to apply a patch to fix this issue.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6773
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Hannibal0x (VulDB User)
References
Affected Vendor
HKUDS
View all reports →