VYPR

Chainlit

by Pypi

CVEs (1)

  • CVE-2026-86099HigSep 9, 2026
    risk 0.53cvss 8.2epss

    Chainlit through 2.12.0 fails to validate the client-supplied socket.io sessionId parameter, allowing unauthenticated attackers to traverse filesystem paths by injecting absolute or relative path sequences. Attackers can craft malicious sessionId values that escape the upload…