Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
chainlit 2.8.3 | Vulnerabilities | Sonatype Guide
pypi
chainlit
2.8.3
chainlit 2.8.3
Published
Oct 6, 2025
•
Policy
compliance
pypi Registry
Developer Trust Score
N/A
Recommended Version:
x.y.z
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Overview
Overview
Versions
167
Versions
167
Vulnerabilities
5
Vulnerabilities
5
Dependencies
22
Dependencies
22
Severity
Critical
(0)
High
(2)
Medium
(2)
Low
(1)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
6.5
CVE-2026-22218
Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-controlled path value, causing the server to copy the referenced file into the attacker’s session. The resulting element identifier (chainlitKey) can then be used to retrieve the file contents via /project/file/<chainlitKey>, allowing disclosure of any file readable by the Chainlit service.
affected
Severity
Medium
Published
Jan 20, 2026
7.7
CVE-2026-22219
Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with the SQLAlchemy data layer backend. An authenticated client can provide a user-controlled url value in an Element, which is fetched by the SQLAlchemy element creation logic using an outbound HTTP GET request. This allows an attacker to make arbitrary HTTP requests from the Chainlit server to internal network services or cloud metadata endpoints and store the retrieved responses via the configured storage provider.
affected
Severity
High
Published
Jan 20, 2026
2.3
CVE-2025-68492
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
affected
Severity
Low
Published
Jan 15, 2026
5.3
sonatype-2026-000008
chainlit - Path Traversal
affected
Severity
Medium
Published
Jan 5, 2026
8.8
sonatype-2025-007362
chainlit - Authorization Bypass Through User-Controlled Key
affected
Severity
High
Published
Dec 1, 2025