chainlitGHSA-v492-6xx2-p57g
Chainlit contains an authorization bypass vulnerability
Low4.2CVE-2025-68492 · Published Jan 14, 2026 · updated Jul 7, 2026
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| chainlit PyPI | < 2.8.5 | 2.8.5 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-639
- Also known as
- CVE-2025-68492, PYSEC-2026-1238
More chainlit advisories
All chainlit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 25 | chainlit: server-side request forgery | High7.2 | 2.12.0 |
| Aug 25 | Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution | Critical9.8 | 2.12.0 |
| Jun 22 | Chainlit contains a session hijacking vulnerability | Critical7.4 | 2.10.1 |
| Jan 20 | Chainlit contain a server-side request forgery (SSRF) vulnerability | High7.7 | 2.9.4 |
| Jan 20 | chainlit: arbitrary file read | Medium6.5 | 2.9.4 |