chainlit

2 known vulnerabilities in chainlit, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86099 CVSS 8.8 high Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to…
  • CVE-2026-82290 CVSS 6.0 medium Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or…