CVE-2025-68492Medium· 4.2▾ SunlitChainlit contains an authorization bypass vulnerability
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
chainlit < 2.8.5Upgrade to a patched release:
chainlit 2.8.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56104High· 7.4Chainlit contains a session hijacking vulnerability
CVE-2026-45018Critical· 9.8Chainlit is a Python framework for building production-ready conversational AI applications
CVE-2026-45019High· 7.2Chainlit is a Python framework for building production-ready conversational AI applications
CVE-2026-22219High· 7.7Chainlit contain a server-side request forgery (SSRF) vulnerability
CVE-2026-86099High· 8.2Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences