Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-45018: Chainlit allows remote code execution when MCP enabled

CVE-2026-45018 · published 9 days ago
Summary

If your Chainlit setup turns on the MCP feature, anyone who can reach the /mcp endpoint can run any command on your server. This happens because the system only checks the program name, not its arguments, letting attackers execute code. Disable MCP or upgrade to version 2.12.0 to stop the risk.

What to do
  • Update chainlit to version 2.12.0.
Affected software
Ecosystem VendorProductAffected versions
chainlit chainlit >= 2.4.0rc0, < 2.12.0
pip chainlit >= 2.4.0rc0, <= 2.11.1
Fix: upgrade to 2.12.0
Original advisory text
Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string. The validate_mcp_command() function in backend/chainlit/mcp.py checks only the executable name against config.features.mcp.stdio.allowed_executables and passes unchecked arguments to StdioServerParameters in backend/chainlit/server.py. Because npx supports the -c argument, an attacker can execute arbitrary shell commands with the privileges of the Chainlit process. If allowed_executables is unset, its None default is treated as allowing every executable. This issue is fixed in version 2.12.0.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-78OS Command Injection
Timeline
Published25 Aug 2026
Updated3 Sep 2026
First seen25 Aug 2026
Sources
CVE-2026-45018 · MITRE
Monitor software like this
Free during beta