CVE 4.2 MEDIUM

CVE-2025-68492_CVE-2025-68492

4.2 / 10
MEDIUM
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Description

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

Basic Information

ID CVE-2025-68492
Source jpcert
Published Jan 14, 2026 at 06:27

Affected Product

Vendor Chainlit
Product Chainlit
Version prior to 2.8.5
Affected Versions Chainlit Chainlit prior to 2.8.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.