CVE-2026-45018 | Chainlit up to 2.11.x MCP Endpoint backend/chainlit/mcp.py validate_mcp_command fullCommand os command injection

SecurityVulns

A vulnerability categorized as critical has been discovered in Chainlit up to 2.11.x. The affected element is the function validate_mcp_command of the file backend/chainlit/mcp.py of the component MCP Endpoint. The manipulation of the argument fullCommand results in os command injection.

This vulnerability is cataloged as CVE-2026-45018. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More