Vulnerability GHSA-c39v-8hrw-h448
High Risk
HIGH RISK
CVSS Score: 7.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 22, 2026 at 06:34 PM UTC
Chainlit contains a session hijacking vulnerability
0.1.0 - 2.10.0
0.1.0 - 2.10.0
Summary
Chainlit contains a session hijacking vulnerability
Details
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
21 days ago
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
2.4.0rc0 - 2.11.1 PYSEC-2026-3811
2.4.0rc0 - 2.11.1 PYSEC-2026-3811
Critical
21 days ago
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
2.4.0rc0 - 2.11.1 PYSEC-2026-3812
2.4.0rc0 - 2.11.1 PYSEC-2026-3812
High Risk
1 month ago
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
2.4.0rc0 - 2.11.1 GHSA-hvfh-5mj3-5f3j
2.4.0rc0 - 2.11.1 GHSA-hvfh-5mj3-5f3j
Critical
1 month ago
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
2.4.0rc0 - 2.11.1 GHSA-w3fx-mc44-mf6j
2.4.0rc0 - 2.11.1 GHSA-w3fx-mc44-mf6j
High Risk
2 months ago
Chainlit contain a server-side request forgery (SSRF) vulnerability
0.1.0 - 2.9.3 PYSEC-2026-1237
0.1.0 - 2.9.3 PYSEC-2026-1237
Impacted packages
Timeline
Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Fixed (2.10.1)
6 months ago
March 27, 2026 at 07:27 AM UTC
Last Modified
1 hour ago
October 01, 2026 at 05:56 PM UTC