chainlit is vulnerable to Path Traversal
55
Medium Risk
Affected versions of this package are vulnerable to improper handling of user-controlled custom thread element updates. By forging update requests with crafted element data, an attacker could inject unauthorized fields (such as file paths or URLs), potentially leading to unintended file access or manipulation of thread elements. The issue stems from insufficient input validation and trust in client-supplied element attributes, which is mitigated by sanitizing custom element data before processing.
You are affected if you are using a version that falls within the vulnerable range.
chainlit is vulnerable to Path Traversal in versions 2.0.0 - 2.9.3.
Upgrade the chainlit library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant