CVE-2026-22218: Chainlit

Medium severity, CVSS 6.5. EPSS: 9.5% chance of exploitation in the next 30 days.

Chainlit versions prior to 2.9.4 contain an arbitrary file read vulnerability in the /project/element update flow. An authenticated client can send a custom Element with a user-controlled path value, causing the server to copy the referenced file into the attacker’s session. The resulting element identifier (chainlitKey) can then be used to retrieve the file contents via /project/file/<chainlitKey>, allowing disclosure of any file readable by the Chainlit service.

Affected products

  • Chainlit Chainlit: before 2.9.4 (fixed in 2.9.4)

Published 2026-01-20. Last modified 2026-07-14.