CVE-2026-45019

Source
https://cve.org/CVERecord?id=CVE-2026-45019
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45019.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45019
Aliases
Published
2026-08-25T19:20:59Z
Modified
2026-09-11T03:30:37Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access
Details

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http transports, ConnectSseMCPRequest and ConnectStreamableHttpMCPRequest in backend/chainlit/types.py accept a user-controlled url and optional headers dictionary without scheme validation, private-address filtering, or an allowlist. The connect_mcp handler in backend/chainlit/server.py passes these values to sse_client() or streamablehttp_client(), allowing the Chainlit server to make blind outbound requests to arbitrary internal or external services, including cloud metadata endpoints, with attacker-controlled Authorization and Cookie headers. The SSE URL sink has existed since 2.4.0rc0, while attacker-controlled header forwarding and streamable-http support were added in 2.6.4. The response is consumed internally and not returned, but the attacker can issue state-changing authenticated requests, discover internal services, scan ports, and probe metadata endpoints. This issue is fixed in version 2.12.0.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-918"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45019.json"
}
References

Affected packages

Git / github.com/chainlit/chainlit

Affected ranges

Type
GIT
Repo
https://github.com/chainlit/chainlit
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.4.0rc0"
        },
        {
            "fixed":  "2.12.0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.10.0
2.10.1
2.11.0
2.11.1
2.4.0
2.4.0rc0
2.4.1
2.4.2
2.4.201
2.4.3
2.4.301
2.4.302
2.4.400
2.5.5
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.1.1
2.7.2
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45019.json"