Chainlit 2.12.0 patches critical unauthenticated RCE and SSRF flaws in MCP feature
Two security vulnerabilities, CVE-2026-45018 (CVSS 9.8) and CVE-2026-45019 (CVSS 7.2), were disclosed in Chainlit versions 2.4.0rc0 through 2.11.0, affecting installations with the MCP feature enabled. The first flaw allowed unauthenticated attackers to execute arbitrary commands via the stdio transport by supplying a crafted command string that bypassed incomplete argument validation. The second vulnerability enabled unauthenticated server-side request forgery through SSE and streamable-HTTP endpoints, which made outbound requests to internal or metadata hosts using caller-controlled headers. Both issues were reported by SPL Security researchers Vipin and Stephen, who demonstrated working exploits against version 2.11.0. Chainlit 2.12.0, released on August 25, 2026, removes client-supplied command execution and addresses the SSRF path; operators are advised to upgrade immediately and restart the service to ensure the patched code is loaded.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in