Chainlit released version 2.12.0 to remediate two unauthenticated vulnerabilities in its Model Context Protocol /mcp endpoint: critical command injection/RCE, CVE-2026-45018 (CVSS 9.8), and high-severity SSRF, CVE-2026-45019 (CVSS 7.2). Versions 2.4.0rc0 through 2.11.x are affected when features.mcp.enabled = true. The command-injection issue allowed attackers to submit client-controlled stdio fullCommand values; configurations with no allowed_executables restriction could allow arbitrary commands through permitted tooling such as npx -c, executing under the Chainlit process account.
The SSRF issue let attackers supply arbitrary HTTP/SSE MCP URLs and headers, enabling requests to loopback and private-network services, Docker sockets, Kubernetes APIs, databases, and cloud metadata endpoints such as 169.254.169.254, with possible exposure of temporary cloud credentials. Version 2.12.0 requires server-side named configuration for stdio MCP servers and adds explicit opt-in allowlisting, destination revalidation, sensitive-header filtering, and redirect blocking for user-provided HTTP/SSE connections. Organizations should upgrade promptly; where that is not immediately possible, disable MCP with features.mcp.enabled = false, enforce authentication, and block server egress to internal networks and cloud-metadata services.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
SPL Security reported and Chainlit confirmed two MCP `/mcp` endpoint vulnerabilities: critical command injection/RCE (SPL-2026-001/CVE-2026-45018) and high-severity SSRF (SPL-2026-002/CVE-2026-45019). The researchers supplied working proof-of-concept exploits.
CVE-2026-45018's stdio command validation allowed arbitrary host binaries when `features.mcp.stdio.allowed_executables` was unset, and validated only the executable basename while leaving arguments unchecked. Even configured allowlists could be bypassed with dual-use executables such as `npx` using `-c` or `--call` to run attacker-supplied commands.
Chainlit released version 2.12.0 to address unauthenticated command injection in the stdio MCP transport and SSRF in SSE and streamable-HTTP MCP connections affecting versions 2.4.0rc0 through 2.11.x when MCP was enabled. The release removes client-controlled stdio commands, requires server-defined named MCP servers, and adds opt-in URL allowlisting, header filtering, redirect blocking, and destination revalidation for user-provided MCP connections.
Chainlit disabled its Model Context Protocol (MCP) functionality by default beginning with version 2.7.0, limiting exposure to deployments that explicitly enabled `features.mcp.enabled`.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.