Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v492-6xx2-p57g

Опубликовано: 14 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3
CVSS3: 4.2

Описание

Chainlit contains an authorization bypass vulnerability

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

Пакеты

Наименование

chainlit

pip
Затронутые версииВерсия исправления

< 2.8.5

2.8.5

EPSS

Процентиль: 8%
0.0003
Низкий

2.3 Low

CVSS4

4.2 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 4.2
nvd
24 дня назад

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

EPSS

Процентиль: 8%
0.0003
Низкий

2.3 Low

CVSS4

4.2 Medium

CVSS3

Дефекты

CWE-639