Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3811
  • PyPI/chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access 10 Sep
  • Fix available
  • Severity - 7.2 (High)
PYSEC-2026-3812
  • PyPI/chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution 10 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-hvfh-5mj3-5f3j
  • PyPI/chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access 25 Aug
  • Fix available
  • Severity - 7.2 (High)
GHSA-w3fx-mc44-mf6j
  • PyPI/chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution 25 Aug
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-1237
  • PyPI/chainlit
Chainlit contain a server-side request forgery (SSRF) vulnerability 07 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-1238
  • PyPI/chainlit
Chainlit contains an authorization bypass vulnerability 07 Jul
  • Fix available
  • Severity - 2.3 (Low)
GHSA-2g59-m95p-pgfq
  • PyPI/chainlit
Chainlit contain a server-side request forgery (SSRF) vulnerability 20 Jan
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-598
  • PyPI/chainlit
See record for full details 20 Jan
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-v492-6xx2-p57g
  • PyPI/chainlit
Chainlit contains an authorization bypass vulnerability 14 Jan
  • Fix available
  • Severity - 2.3 (Low)