id: PYSEC-2026-1238 published: "2026-07-07T16:03:18.754455Z" modified: "2026-07-07T17:23:53.606108Z" aliases: - CVE-2025-68492 - GHSA-v492-6xx2-p57g summary: Chainlit contains an authorization bypass vulnerability details: Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product. affected: - package: name: chainlit ecosystem: PyPI purl: pkg:pypi/chainlit ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 2.8.5 versions: - 0.1.0 - 0.1.1 - 0.1.101 - 0.1.102 - 0.1.103 - 0.2.0 - 0.2.1 - 0.2.101 - 0.2.102 - 0.2.103 - 0.2.104 - 0.2.105 - 0.2.106 - 0.2.107 - 0.2.108 - 0.2.109 - 0.2.110 - 0.2.111 - 0.3.0 - 0.4.0 - 0.4.1 - 0.4.101 - 0.4.2 - 0.4.3 - 0.5.0 - 0.5.1 - 0.5.2 - 0.6.0 - 0.6.1 - 0.6.2 - 0.6.3 - 0.6.4 - 0.6.401 - 0.6.402 - 0.7.0 - 0.7.1 - 0.7.2 - 0.7.3 - 0.7.301 - 0.7.400 - 0.7.500 - 0.7.501 - 0.7.600rc0 - 0.7.600rc1 - 0.7.601rc0 - 0.7.602 - 0.7.602rc0 - 0.7.603 - 0.7.604 - 0.7.604rc0 - 0.7.604rc1 - 0.7.604rc2 - 0.7.700 - 1.0.0 - 1.0.0rc0 - 1.0.0rc1 - 1.0.0rc2 - 1.0.0rc3 - 1.0.100 - 1.0.101 - 1.0.200 - 1.0.300 - 1.0.301 - 1.0.400 - 1.0.401 - 1.0.500 - 1.0.501 - 1.0.502 - 1.0.503 - 1.0.504 - 1.0.505 - 1.0.506 - 1.1.0 - 1.1.0rc0 - 1.1.0rc1 - 1.1.101 - 1.1.200 - 1.1.201 - 1.1.202 - 1.1.300 - 1.1.300rc0 - 1.1.300rc1 - 1.1.300rc2 - 1.1.300rc3 - 1.1.300rc4 - 1.1.300rc5 - 1.1.301 - 1.1.302 - 1.1.303 - 1.1.304 - 1.1.305 - 1.1.306 - 1.1.400 - 1.1.400rc0 - 1.1.400rc1 - 1.1.401 - 1.1.402 - 1.1.403rc0 - 1.1.404 - 1.2.0 - 1.2.0rc0 - 1.3.0 - 1.3.0rc0 - 1.3.0rc1 - 1.3.1 - 1.3.2 - 2.0.0 - 2.0.1 - 2.0.2 - 2.0.3 - 2.0.4 - 2.0.5 - 2.0.6 - 2.0.601 - 2.0.602 - 2.0.603 - 2.0.dev0 - 2.0.dev1 - 2.0.dev2 - 2.0rc0 - 2.0rc1 - 2.1.0 - 2.1.1 - 2.1.2 - 2.2.0 - 2.2.1 - 2.3.0 - 2.4.0 - 2.4.0rc0 - 2.4.1 - 2.4.2 - 2.4.201 - 2.4.3 - 2.4.301 - 2.4.302 - 2.4.400 - 2.5.5 - 2.6.0 - 2.6.1 - 2.6.2 - 2.6.3 - 2.6.4 - 2.6.5 - 2.6.6 - 2.6.7 - 2.6.8 - 2.6.9 - 2.7.0 - 2.7.1 - 2.7.1.1 - 2.7.2 - 2.8.0 - 2.8.1 - 2.8.2 - 2.8.3 - 2.8.4 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2025-68492 - type: WEB url: https://github.com/Chainlit/chainlit/pull/2637 - type: WEB url: https://github.com/Chainlit/chainlit/commit/8f1153db439eca58ae5c50c8276ba6fdd311448e - type: PACKAGE url: https://github.com/Chainlit/chainlit - type: WEB url: https://github.com/Chainlit/chainlit/releases - type: WEB url: https://github.com/Chainlit/chainlit/releases/tag/2.8.5 - type: WEB url: https://jvn.jp/en/jp/JVN34964581 - type: PACKAGE url: https://pypi.org/project/chainlit - type: ADVISORY url: https://github.com/advisories/GHSA-v492-6xx2-p57g severity: - type: CVSS_V3 score: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N