{"data":{"id":"162d8574-2040-4cd6-a62a-c66b1d3b3ba2","title":"GHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access","summary":"Chainlit versions 2.4.0 through 2.11.x have a Server-Side Request Forgery vulnerability (SSRF, where an attacker tricks a server into making requests to unintended targets) in the MCP (Model Context Protocol) feature that is disabled by default. When MCP is enabled, an unauthenticated attacker can force the Chainlit server to make HTTP requests to internal network services or cloud metadata endpoints by sending a crafted request to the `/mcp` endpoint with a malicious URL and custom headers like Authorization and Cookie.","solution":"Update Chainlit to version 2.12.0 (releasing 2026-08-25), which patches the vulnerability. Alternatively, keep MCP disabled by ensuring `features.mcp.enabled = false` in `.chainlit/config.toml` (the default setting since v2.7.0).","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-hvfh-5mj3-5f3j","publishedAt":"2026-08-25T19:21:40.000Z","cveId":"CVE-2026-45019","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["chainlit@>= 2.4.0rc0, <= 2.11.1 (fixed: 2.12.0)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["Chainlit","MCP (Model Context Protocol)"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-08-25T19:21:40.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":["AML.T0010"]}}