Loading
Build Conversational AI.
Declares an LLM dependency since 2025-03-09 (version 2.4.0rc0).
Advisories that name chainlit as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-45019GHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access | High | >= 2.4.0rc0, <= 2.11.1 | 2.12.0 | 2026-08-25 |
| CVE-2026-45018GHSA-w3fx-mc44-mf6j: Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution | Critical | >= 2.4.0rc0, <= 2.11.1 | 2.12.0 | 2026-08-25 |
As declared in PyPI metadata for version 2.12.0. Optional extras are listed with their extra name.
Among the packages in the registry; not every dependent on PyPI.