Intel

AIKIDO-2024-10355

chainlit is vulnerable to Unauthorized File Access

Unauthorized File Access Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

96

Critical Risk

This Affects:

pythonchainlit
0.1.1 - 1.3.0rc0

TL;DR

Affected versions of the package are vulnerable to unauthorized file access in the file_upload method. This flaw allows any user with an active session to access files they should not be authorized to view, potentially exposing sensitive information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

chainlit is vulnerable to Unauthorized File Access in versions 0.1.1 - 1.3.0rc0.

How to fix this

Upgrade the chainlit library to the patch version.