chainlit is vulnerable to Insufficient Session Expiration
30
Low Risk
Affected versions of this package are vulnerable to improper authentication cookie handling because the clear_auth_cookie function does not explicitly specify the secure and samesite attributes when deleting authentication cookies. This can lead to failed logout attempts, especially if CHAINLIT_COOKIE_SAMESITE is set to a non-default value, as the browser may not clear the cookie correctly.
You are affected if you are using a version that falls within the vulnerable range.
chainlit is vulnerable to Insufficient Session Expiration in versions 2.0.0 - 2.2.1.
Upgrade the chainlit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant