SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-45019

HIGH · CVSS 7.2 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Chainlit deployments with the features.mcp.enabled setting exposed the POST /mcp endpoint without authentication, allowing attackers to send arbitrary requests to internal or external services, including sensitive cloud metadata endpoints. This vulnerability can lead to unauthorized access, service discovery, and potential data exfiltration due to the lack of scheme validation and filtering on user-controlled URLs and headers. Organizations using affected versions of Chainlit, particularly those with enabled MCP features, should prioritize upgrading to version 2.12.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-45019
Severity
HIGH
CVSS
7.2
EPSS
0.32%

Original NVD Description

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse and streamable-http transports, ConnectSseMCPRequest and ConnectStreamableHttpMCPRequest in backend/chainlit/types.py accept a user-controlled url and optional headers dictionary without scheme validation, private-address filtering, or an allowlist. The connect_mcp handler in backend/chainlit/server.py passes these values to sse_client() or streamablehttp_client(), allowing the Chainlit server to make blind outbound requests to arbitrary internal or external services, including cloud metadata endpoints, with attacker-controlled Authorization and Cookie headers. The SSE URL sink has existed since 2.4.0rc0, while attacker-controlled header forwarding and streamable-http support were added in 2.6.4. The response is consumed internally and not returned, but the attacker can issue state-changing authenticated requests, discover internal services, scan ports, and probe metadata endpoints. This issue is fixed in version 2.12.0.