{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/chainlit--2.12.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:chainlit:chainlit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-86099"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Chainlit (\u003c= 2.12.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","path-traversal","arbitrary-deletion"],"_cs_type":"advisory","_cs_vendors":["Chainlit"],"content_html":"\u003cp\u003eChainlit versions up to and including 2.12.0 contain a critical path traversal vulnerability (CVE-2026-86099) originating from the improper validation of the client-supplied \u003ccode\u003esessionId\u003c/code\u003e parameter within \u003ccode\u003esocket.io\u003c/code\u003e communications. An unauthenticated attacker can exploit this flaw by submitting crafted \u003ccode\u003esessionId\u003c/code\u003e values containing path traversal sequences, such as dot-dot-slash patterns. This manipulation allows the attacker to break out of the application-defined upload directory. Once the escape is successful, the attacker can target sensitive files or directories, ultimately triggering recursive deletion of any path accessible to the service process. The impact is significant, as it enables destructive actions against the underlying filesystem without requiring prior authentication. Given the nature of the vulnerability, defenders should prioritize patching and monitoring for anomalous \u003ccode\u003esocket.io\u003c/code\u003e traffic targeting the session identifier.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to delete arbitrary directories on the host server. This can lead to total service disruption, data loss, or the deletion of critical system or application components, depending on the service account's permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch Chainlit to a version newer than 2.12.0 as soon as a fix is made available by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for socket.io traffic containing unconventional characters in the \u003ccode\u003esessionId\u003c/code\u003e parameter, specifically path traversal sequences like \u003ccode\u003e../\u003c/code\u003e or \u003ccode\u003e..\\\\\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eEnsure the Chainlit service process is running with the principle of least privilege, restricting its write and delete permissions to only the necessary directories.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T14:58:27Z","date_published":"2026-09-09T14:58:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-chainlit-path-traversal/","summary":"Chainlit versions 2.12.0 and earlier are vulnerable to an unauthenticated path traversal attack via the socket.io sessionId parameter, enabling arbitrary directory deletion.","title":"Path Traversal and Arbitrary Deletion in Chainlit","url":"https://feed.craftedsignal.io/briefs/2026-09-chainlit-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Chainlit (\u003c= 2.12.0)","version":"https://jsonfeed.org/version/1.1"}