{"id":"CVE-2026-45018","title":"Chainlit is a Python framework for building production-ready conversational AI applications","summary":"Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"chainlit","product":"chainlit","affected":["chainlit >= 2.4.0rc0, <= 2.11.1"],"patched":["chainlit 2.12.0"],"published":"2026-08-25","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:07:31.353","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45018","references":[{"url":"https://github.com/Chainlit/chainlit/blob/2.12.0/docs/security-advisory-2026-mcp.md#spl-2026-001--command-injection-via-mcp-stdio","label":"security-advisories@github.com"},{"url":"https://github.com/Chainlit/chainlit/commit/0565fd0eccb915fce159929598b053ed79f6e0c9","label":"security-advisories@github.com"},{"url":"https://github.com/Chainlit/chainlit/releases/tag/2.12.0","label":"security-advisories@github.com"},{"url":"https://github.com/Chainlit/chainlit/security/advisories/GHSA-w3fx-mc44-mf6j","label":"security-advisories@github.com"},{"url":"https://github.com/Chainlit/chainlit/security/advisories/GHSA-w3fx-mc44-mf6j","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-w3fx-mc44-mf6j"},{"url":"https://github.com/Chainlit/chainlit"},{"url":"https://pypi.org/project/chainlit"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45018"}],"tags":["nvd","ghsa","pip","osv"],"epss":0.00653,"epssPercentile":0.49857,"aliases":["GHSA-w3fx-mc44-mf6j","PYSEC-2026-3812"],"ecosystem":"pip","ingestedAt":"2026-08-25T19:31:03.133Z","slug":"CVE-2026-45018","body":"## Overview\n\nChainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chainlit/mcp.py checks only the executable name against config.features.mcp.stdio.allowed_executables and passes unchecked arguments to StdioServerParameters in backend/chainlit/server.py. Because npx supports the -c argument, an attacker can execute arbitrary shell commands with the privileges of the Chainlit process. If allowed_executables is unset, its None default is treated as allowing every executable. This issue is fixed in version 2.12.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-45018)\n\nAffected packages:\n\n- `chainlit >= 2.4.0rc0, <= 2.11.1`\n\nPatched in:\n\n- `chainlit 2.12.0`\n\nSource: https://github.com/advisories/GHSA-w3fx-mc44-mf6j","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}