GHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
Summary
Chainlit versions 2.4.0 through 2.11.x have a Server-Side Request Forgery vulnerability (SSRF, where an attacker tricks a server into making requests to unintended targets) in the MCP (Model Context Protocol) feature that is disabled by default. When MCP is enabled, an unauthenticated attacker can force the Chainlit server to make HTTP requests to internal network services or cloud metadata endpoints by sending a crafted request to the `/mcp` endpoint with a malicious URL and custom headers like Authorization and Cookie.
Solution / Mitigation
Update Chainlit to version 2.12.0 (releasing 2026-08-25), which patches the vulnerability. Alternatively, keep MCP disabled by ensuring `features.mcp.enabled = false` in `.chainlit/config.toml` (the default setting since v2.7.0).
Vulnerability Details
EPSS: 0.0%
Yes
August 25, 2026
Classification
Taxonomy References
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-hvfh-5mj3-5f3j
First tracked: August 25, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 92%