chainlit is vulnerable to Insufficient Session Expiration
30
Low Risk
Affected versions of this package are vulnerable to improper authentication cookie handling because the clear_auth_cookie function does not explicitly specify the secure and samesite attributes when deleting authentication cookies. This can lead to failed logout attempts, especially if CHAINLIT_COOKIE_SAMESITE is set to a non-default value, as the browser may not clear the cookie correctly.
You are affected if you are using a version that falls within the vulnerable range.
chainlit is vulnerable to Insufficient Session Expiration in versions 2.0.0 - 2.2.1.
Upgrade the chainlit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant