Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c39v-8hrw-h448

Опубликовано: 22 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.

EPSS

Процентиль: 35%
0.00417
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 8.2
nvd
3 месяца назад

Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSocket session restoration without ownership verification. Attackers can exploit the restore_existing_session path to assume a victim's permissions and roles, enabling unauthorized invocation of tools and access to data restricted to the authenticated victim.

EPSS

Процентиль: 35%
0.00417
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-862