Known Vulnerabilities for Chainlit by Chainlit
Listed below are 2 of the newest known vulnerabilities associated with "Chainlit" by "Chainlit".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86099 json | Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attacke... | Not Provided | 2026-09-09 | 2026-09-09 |
| CVE-2026-82290 json | Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers ... | Not Provided | 2026-08-28 | 2026-08-31 |
| CVE-2026-56104 json | Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inheri... | Not Provided | 2026-06-22 | 2026-07-14 |
| CVE-2026-45019 json | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chai... | Not Provided | 2026-08-25 | 2026-08-27 |
| CVE-2026-45018 json | Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chai... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-22219 json | Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update fl... | Not Provided | 2026-01-20 | 2026-07-14 |
| CVE-2026-22218 json | Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authent... | Not Provided | 2026-01-20 | 2026-07-14 |