chainlit@2.12.0

Build Conversational AI.

Direct Vulnerabilities

Known vulnerabilities in the chainlit package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Authorization Bypass Through User-Controlled Key

chainlit is a Build Conversational AI.

Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the feedback PUT and DELETE endpoints in backend/chainlit/server.py. An authenticated attacker can modify or delete other users’ feedback by supplying arbitrary feedback identifiers. This corrupts human-rating data used for model evaluation and can undermine the integrity of stored feedback records for anyone relying on Chainlit’s review workflow.

How to fix Authorization Bypass Through User-Controlled Key?

There is no fixed version for chainlit.

[1.0.500,)