Vulnerability GHSA-c39v-8hrw-h448

High Risk
HIGH RISK
CVSS Score: 7.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 22, 2026 at 06:34 PM UTC
Chainlit contains a session hijacking vulnerability
0.1.0 - 2.10.0
0.1.0 - 2.10.0

Summary

Chainlit contains a session hijacking vulnerability

Details

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.

Impacted packages

Timeline

Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Fixed (2.10.1)
6 months ago
March 27, 2026 at 07:27 AM UTC
Last Modified
1 hour ago
October 01, 2026 at 05:56 PM UTC