High severity8.2NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86099
CVE-2026-86099
Description
Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious sessionId values that escape the upload directory and recursively delete arbitrary directories accessible to the service process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Package: https://pypi.org/project/chainlit
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.