Chainlit is a focused application framework for building conversational AI interfaces, with its vulnerability profile centering on path-traversal and server-side request-forgery weaknesses in the core product. These durable signals reflect the framework's role in handling user input and making outbound requests on behalf of backend services, common fault lines in web-facing AI application layers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chainlit over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-56104HIGH Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid ses | Jun 22, 2026 | 8.2 | 33 | NO | NO |
CVE-2026-22219HIGH Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with the SQLAlchemy data layer backe | Jan 20, 2026 | 7.7 | 33 | NO | NO |
CVE-2026-22218MEDIUM Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-con | Jan 20, 2026 | 6.5 | 33 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chainlit.
Media articles that mention a CVE ID that affects a product developed by Chainlit — matched by CVE ID, not by vendor name.