10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether chainlit is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.4
CVE-2026-56104
Chainlit contains a session hijacking vulnerability
CRITICAL 9.8
CVE-2026-45018
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
HIGH 7.2
CVE-2026-45019
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
CRITICAL 9.8
CVE-2026-45018
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
HIGH 7.2
CVE-2026-45019
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
HIGH 7.7
CVE-2026-22219
Chainlit contain a server-side request forgery (SSRF) vulnerability
MEDIUM 4.2
CVE-2025-68492
Chainlit contains an authorization bypass vulnerability
HIGH 7.7
CVE-2026-22219
Chainlit contain a server-side request forgery (SSRF) vulnerability
MEDIUM 4.2
CVE-2025-68492
Chainlit contains an authorization bypass vulnerability
MEDIUM 6.5
CVE-2026-22218
CVE-2026-22218
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes