Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3811
  • PyPI/chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access 10 Sep
  • Fix available
  • Severity - 7.2 (High)
PYSEC-2026-3812
  • PyPI/chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution 10 Sep
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-86099
  • github.com/chainlit/chainlit
Chainlit through 2.12.0 Path Traversal via socket.io sessionId 09 Sep
  • Fix available
  • Severity - 8.8 (High)
CVE-2026-82290
  • github.com/chainlit/chainlit
Chainlit Feedback Endpoints Missing Ownership Validation 28 Aug
  • Fix available
  • Severity - 6.0 (Medium)
GHSA-hvfh-5mj3-5f3j
  • PyPI/chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access 25 Aug
  • Fix available
  • Severity - 7.2 (High)
CVE-2026-45019
  • github.com/chainlit/chainlit
Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access 25 Aug
  • Fix available
  • Severity - 7.2 (High)
GHSA-w3fx-mc44-mf6j
  • PyPI/chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution 25 Aug
  • Fix available
  • Severity - 9.8 (Critical)
CVE-2026-45018
  • github.com/chainlit/chainlit
Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution 25 Aug
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2026-1237
  • PyPI/chainlit
Chainlit contain a server-side request forgery (SSRF) vulnerability 07 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-1238
  • PyPI/chainlit
Chainlit contains an authorization bypass vulnerability 07 Jul
  • Fix available
  • Severity - 2.3 (Low)
GHSA-c39v-8hrw-h448
  • PyPI/chainlit
Chainlit contains a session hijacking vulnerability 22 Jun
  • Fix available
  • Severity - 9.1 (Critical)
CVE-2026-56104
  • github.com/chainlit/chainlit
Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration 22 Jun
  • Fix available
  • Severity - 8.8 (High)
GHSA-2g59-m95p-pgfq
  • PyPI/chainlit
Chainlit contain a server-side request forgery (SSRF) vulnerability 20 Jan
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-598
  • PyPI/chainlit
See record for full details 20 Jan
  • Fix available
  • Severity - 6.5 (Medium)
CVE-2026-22219
  • github.com/chainlit/chainlit
Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element 19 Jan
  • Fix available
  • Severity - 8.3 (High)
CVE-2026-22218
  • github.com/chainlit/chainlit
Chainlit < 2.9.4 Arbitrary File Read via /project/element 19 Jan
  • Fix available
  • Severity - 7.1 (High)