MEDIUM 4.2 PyPI
Chainlit contains an authorization bypass vulnerability
GHSA-v492-6xx2-p57g · CVE-2025-68492
Published · Modified
Description
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-68492
- WEB https://github.com/Chainlit/chainlit/pull/2637
- WEB https://github.com/Chainlit/chainlit/commit/8f1153db439eca58ae5c50c8276ba6fdd311448e
- PACKAGE https://github.com/Chainlit/chainlit
- WEB https://github.com/Chainlit/chainlit/releases
- WEB https://github.com/Chainlit/chainlit/releases/tag/2.8.5
- WEB https://jvn.jp/en/jp/JVN34964581
Ready to move
Start Securing
Free, no credit card | First findings in minutes