Skip to content

[GHSA-8ffj-4hx4-9pgf] lightrag-hku: JWT Algorithm Confusion Vulnerability #7336

Open
nomore8797 wants to merge 1 commit intonomore8797/advisory-improvement-7336from
nomore8797-GHSA-8ffj-4hx4-9pgf
Open

[GHSA-8ffj-4hx4-9pgf] lightrag-hku: JWT Algorithm Confusion Vulnerability #7336
nomore8797 wants to merge 1 commit intonomore8797/advisory-improvement-7336from
nomore8797-GHSA-8ffj-4hx4-9pgf

Conversation

@nomore8797
Copy link
Copy Markdown

Updates

  • CVSS v3

Comments
Hello, GitHub Community Guidelines!
I noticed that the APIs are completely unreliable for everyone, very often fall off for various reasons. Also, do not inspire confidence tokens, they are long and strictly confidential, they need to be stored in a safe place and not get confused about "what from what?" It is not at all convenient and even large systems fail. What if you have a big project or a generative agent who decided to connect himself? I fully support the integration, but as a Safe Architect, I am primarily for the safety and stability of the systems being developed, and as I suggested replacing the author with a solid code, but I propose to revise the integration system more globally and abandon the API in the form in which it is present, namely, remove tokens and unreliable mounts and switch to Safe integration by forming a private code for each system. Forming a Secure Code for Integration can perform agent perfectly. I hope that here, in the virtues of the developers, I will be supported in the fact that integration through the API is obsolete and physically weak for the power and simplicity of the development that we all approached now.

Have a good day.
Respectfully, Olga!

@github
Copy link
Copy Markdown
Collaborator

github commented Apr 8, 2026

Hi there @danielaskdd! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to nomore8797/advisory-improvement-7336 April 8, 2026 17:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants