CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-22219: chainlit before 2.9.4 (exclusive); +1 more affected products

CVE-2026-22219. CVSS 3.1 base score 7.7 (HIGH, NVD). EPSS 0.0506 (percentile 0.92075), scored 2026-10-06.

Affected technology

chainlit · before 2.9.4 (exclusive)
chainlit

Chainlit · 0 to before 2.9.4
Chainlit

Description’s affected range: versions prior to 2.9.4

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required

What an attacker can do

An attacker can make arbitrary HTTP requests from the Chainlit server to internal network services or cloud metadata endpoints and store the retrieved responses via the configured storage provider. Vendor/CNA’s CVSS 4.0 assessment (base score 8.3/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-918
CCR priority
32.1 /100 (P4)
CVSS 3.1
7.7 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N · NVD
EPSS
0.0506 · percentile 0.92096 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-22219.html