Skip to main content

Description

Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-controlled path value, causing the server to copy the referenced file into the attacker’s session. The resulting element identifier (chainlitKey) can then be used to retrieve the file contents via /project/file/<chainlitKey>, allowing disclosure of any file readable by the Chainlit service.

Severity

CVSS 4.0 · CNA7.1 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
SSVC · CISA-ADP
Exploitationpoc
Automatableno
Technical impactpartial

Affected Products

VendorProductAffected versions
ChainlitChainlit
0 to <2.9.4

References

3 Links

Record Details

Published
2026-01-19
Last updated
2026-07-14
Assigner (CNA)
VulnCheck
Credited to
Ido Shani and Gal Zaban of Zafran Security

More from Chainlit

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.