Skip to content
chainlitGHSA-c39v-8hrw-h448

Chainlit contains a session hijacking vulnerability

Critical7.4CVE-2026-56104 · Published Jun 22, 2026 · updated Sep 21, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
chainlit
PyPI
< 2.10.12.10.1
Details and references

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-862
Also known as
CVE-2026-56104

More chainlit advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.