CVE-2025-68492

MEDIUM

Pypi Chainlit < 2.8.5 - IDOR

Title source: rule
STIX 2.1

Description

Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.

References (2)

Core 2
Core References
Third Party Advisory
https://jvn.jp/en/jp/JVN34964581/

Scores

CVSS v3 4.2
EPSS 0.0001
EPSS Percentile 2.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
Chainlit/Chainlit prior to 2.8.5
pypi/chainlit 0 - 2.8.5PyPI
Published Jan 14, 2026
Tracked Since Feb 18, 2026