Chainlit
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 4
en
Verify to analyze this security profile
As of 09/20/2026, Chainlit recorded 4 security vulnerabilities in the last 90 days across 1 products, including 3 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, Chainlit had the most security vulnerabilities in the Chainlit ecosystem, with 4 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-86099Chainlit through 2.12.0 Path Traversal via socket.io sessionId | Exploitation statusNot known exploited | FixYes | Affected productChainlit | Published09/09/2026 | SeverityHigh |
CVE-2026-82290Chainlit Feedback Endpoints Missing Ownership Validation | Exploitation statusPublic exploit | FixYes | Affected productChainlit | Published08/28/2026 | SeverityMedium |
CVE-2026-45019Chainlit: SSRF via MCP SSE and streamable-http transports allows unauthenticated internal network access | Exploitation statusNot known exploited | FixYes | Affected productChainlit | Published08/25/2026 | SeverityHigh |
CVE-2026-45018Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution | Exploitation statusPublic exploit | FixYes | Affected productChainlit | Published08/25/2026 | SeverityCritical |
CVE-2026-56104Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration | Exploitation statusNot known exploited | FixYes | Affected productChainlit | Published06/22/2026 | SeverityHigh |
CVE-2026-22219Chainlit < 2.9.4 SQLAlchemy Data Layer SSRF via /project/element | Exploitation statusPublic exploit | FixYes | Affected productChainlit | Published01/19/2026 | SeverityHigh |
CVE-2026-22218Chainlit < 2.9.4 Arbitrary File Read via /project/element | Exploitation statusPublic exploit | FixYes | Affected productChainlit | Published01/19/2026 | SeverityHigh |
CVE-2025-68492 | Exploitation statusNot known exploited | FixNot confirmed | Affected productChainlit | Published01/14/2026 | SeverityLow |