CVE-2026-45019

Source
https://cve.org/CVERecord?id=CVE-2026-45019
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45019.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45019
Aliases
Published
2026-08-25T19:20:59.339Z
Modified
2026-08-29T03:46:13.917274011Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access
Details

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http transports, ConnectSseMCPRequest and ConnectStreamableHttpMCPRequest in backend/chainlit/types.py accept a user-controlled url and optional headers dictionary without scheme validation, private-address filtering, or an allowlist. The connectmcp handler in backend/chainlit/server.py passes these values to sseclient() or streamablehttp_client(), allowing the Chainlit server to make blind outbound requests to arbitrary internal or external services, including cloud metadata endpoints, with attacker-controlled Authorization and Cookie headers. The SSE URL sink has existed since 2.4.0rc0, while attacker-controlled header forwarding and streamable-http support were added in 2.6.4. The response is consumed internally and not returned, but the attacker can issue state-changing authenticated requests, discover internal services, scan ports, and probe metadata endpoints. This issue is fixed in version 2.12.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45019.json",
    "cwe_ids": [
        "CWE-918"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/chainlit/chainlit

Affected ranges

Type
GIT
Repo
https://github.com/chainlit/chainlit
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "2.4.0rc0"
        },
        {
            "fixed": "2.12.0"
        }
    ]
}

Affected versions

2.*
2.10.0
2.10.1
2.11.0
2.11.1
2.4.0
2.4.0rc0
2.4.1
2.4.2
2.4.201
2.4.3
2.4.301
2.4.302
2.4.400
2.5.5
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.1.1
2.7.2
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.9.0
2.9.1
2.9.2
2.9.3
2.9.4
2.9.5
2.9.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45019.json"