Authorization Bypass Vulnerability in Chainlit by Chainlit
CVE-2025-68492
2.3LOW
What is CVE-2025-68492?
Chainlit versions before 2.8.5 are susceptible to an authorization bypass vulnerability, allowing attackers who gain access to the system to manipulate user-controlled keys. This could enable unauthorized viewing of threads or even assume ownership of those threads, potentially compromising sensitive information and user interactions within the product.
Affected Version(s)
Chainlit prior to 2.8.5
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
