Missing Authorization Affecting chainlit package, versions [,2.10.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.26% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Missing Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-PYTHON-CHAINLIT-17423203
  • published23 Jun 2026
  • disclosed22 Jun 2026
  • creditTanguy Snoeck

Introduced: 22 Jun 2026

CVE-2026-56104  (opens in a new tab)
CWE-862  (opens in a new tab)

How to fix?

Upgrade chainlit to version 2.10.1 or higher.

Overview

chainlit is a Build Conversational AI.

Affected versions of this package are vulnerable to Missing Authorization via the restore_existing_session path in the WebSocket session restoration. An attacker can gain unauthorized access to another user's session and assume their permissions and roles by presenting a valid sessionId without ownership verification.

CVSS Base Scores

version 4.0
version 3.1