chainlit vulnerabilities
CVEs whose affected-version data names the chainlit package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2026-86099High· 8.2Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences
Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious …
CVE-2026-45018Critical· 9.8Chainlit is a Python framework for building production-ready conversational AI applications
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…
CVE-2026-45019High· 7.2Chainlit is a Python framework for building production-ready conversational AI applications
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…
CVE-2026-56104High· 7.4Chainlit contains a session hijacking vulnerability
Chainlit contains a session hijacking vulnerability
CVE-2026-22219High· 7.7Chainlit contain a server-side request forgery (SSRF) vulnerability
Chainlit contain a server-side request forgery (SSRF) vulnerability
CVE-2025-68492Medium· 4.2Chainlit contains an authorization bypass vulnerability
Chainlit contains an authorization bypass vulnerability