CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

Chronological Source Flow
Back

AI Fusion Summary

Recent security reports highlight critical vulnerabilities in DB-GPT and Chainlit. DB-GPT faces two unauthenticated path-traversal arbitrary file writes, CVE-2026-80104 and CVE-2026-73034, affecting upload APIs. While the latest PyPI release fixes the former, the latter remains. Meanwhile, Chainlit 2.12.0 addresses CVE-2026-45018, an unauthenticated RCE via MCP stdio transport, and CVE-2026-45019, an unauthenticated SSRF. These Chainlit flaws require features.mcp.enabled to be true, though MCP is disabled by default since version 2.7.0.
Community Comments
Loading updates...
0