CVE-2025-6773: HKUDS LightRAG File Upload document_routes.py upload_to_input_dir path traversal
A vulnerability was found in HKUDS LightRAG up to 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadtoinputdir of the file lightrag/api/routers/documentroutes.py of the component File Upload. The manipulation of the argument file.filename leads to path traversal. It is possible to launch the attack on the local host. The identifier of the patch is 60777d535b719631680bcf5d0969bdef79ca4eaf. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/lightrag-hkuto a version that resolves this vulnerability.Fixed in 1.3.8 - Upgrade
Upgrade
HKUDS LightRAGto a version that resolves this vulnerability.Fixed in 1.3.8Patch 60777d535b719631680bcf5d0969bdef79ca4eaf
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6773?
CVE-2025-6773 has been declared as critical.
What components are affected by CVE-2025-6773?
CVE-2025-6773 affects the File Upload component in HKUDS LightRAG versions up to 1.3.8.
How can I mitigate CVE-2025-6773?
To mitigate CVE-2025-6773, ensure to upgrade HKUDS LightRAG to a version later than 1.3.8.
What kind of vulnerability is CVE-2025-6773?
CVE-2025-6773 is a file upload vulnerability found in the function upload_to_input_dir.
Is there a known exploit for CVE-2025-6773?
There are currently no public details regarding specific exploits associated with CVE-2025-6773.