Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-01-14 07:16
Updated : 2026-01-14 16:25
NVD link : CVE-2025-68492
Mitre link : CVE-2025-68492
CVE.ORG link : CVE-2025-68492
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
