CVE-2026-45018 – Chainlit
CVSS 9.8
CRITICAL
Zero Day – Immediate Deployment
“An exposed MCP endpoint can turn a crafted command into unauthenticated server takeover.”
Chainlit versions from 2.4.0rc0 before 2.12.0 contain a Critical command injection vulnerability when MCP is enabled. CVE-2026-45018 allows an unauthenticated attacker to abuse the /mcp endpoint and pass malicious arguments to an allowed executable, resulting in arbitrary shell command execution with the privileges of the Chainlit process. The CVSS score is 9.8, which is Critical severity.
The issue is fixed in Chainlit 2.12.0. Public proof-of-concept material is available.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-78
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.