CVE-2026-45018 – Chainlit

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“An exposed MCP endpoint can turn a crafted command into unauthenticated server takeover.”

Chainlit versions from 2.4.0rc0 before 2.12.0 contain a Critical command injection vulnerability when MCP is enabled. CVE-2026-45018 allows an unauthenticated attacker to abuse the /mcp endpoint and pass malicious arguments to an allowed executable, resulting in arbitrary shell command execution with the privileges of the Chainlit process. The CVSS score is 9.8, which is Critical severity.

The issue is fixed in Chainlit 2.12.0. Public proof-of-concept material is available.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-78
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.