VYPR
Medium severity5.3NVD Advisory· Published Aug 28, 2026

CVE-2026-82290

CVE-2026-82290

Description

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.

Affected products

2
  • Chainlit/Chainlitreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <=2.12.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.