Skip to main content

Description

Chainlit versions prior to 2.9.4 contain a server-side request forgery (SSRF) vulnerability in the /project/element update flow when configured with the SQLAlchemy data layer backend. An authenticated client can provide a user-controlled url value in an Element, which is fetched by the SQLAlchemy element creation logic using an outbound HTTP GET request. This allows an attacker to make arbitrary HTTP requests from the Chainlit server to internal network services or cloud metadata endpoints and store the retrieved responses via the configured storage provider.

Severity

CVSS 4.0 · CNA8.3 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
SSVC · CISA-ADP
Exploitationnone
Automatableyes
Technical impactpartial

Affected Products

VendorProductAffected versions
ChainlitChainlit
0 to <2.9.4

References

3 Links

Record Details

Published
2026-01-19
Last updated
2026-07-14
Assigner (CNA)
VulnCheck
Credited to
Ido Shani and Gal Zaban of Zafran Security

More from Chainlit

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-918 · Server-Side Request Forgery

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.