{"api_version":"v1","generated_at":"2026-10-08T04:55:00+00:00","product":{"cve_count":5,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-chainlit-chainlit-ec68ca24e078","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/chainlit","name":"chainlit","next_cursor":null,"observations":[{"affected":"\u2264 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-86099","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86099","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-09T14:49:36.459Z","patch_url":"","primary_source":"","published":"2026-09-09T13:31:59.696Z"},{"affected":"chainlit: \u2264 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-82290","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-82290","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-24T14:20:20.148Z","patch_url":"","primary_source":"","published":"2026-08-28T16:19:07.258Z"},{"affected":">= 2.4.0rc0, < 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-45019","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45019","fixed":"2.12.0.","last_modified":"2026-08-27T14:35:27.308Z","patch_url":"https://github.com/Chainlit/chainlit/security/advisories/GHSA-hvfh-5mj3-5f3j","primary_source":"","published":"2026-08-25T19:20:59.339Z"},{"affected":">= 2.4.0rc0, < 2.12.0","affected_versions_present":true,"cve_id":"CVE-2026-45018","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-45018","fixed":"2.12.0.","last_modified":"2026-08-25T19:33:30.993Z","patch_url":"https://github.com/Chainlit/chainlit/security/advisories/GHSA-w3fx-mc44-mf6j","primary_source":"","published":"2026-08-25T19:18:46.439Z"},{"affected":"< 2.10.1","affected_versions_present":true,"cve_id":"CVE-2026-56104","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-56104","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T21:34:00.565Z","patch_url":"","primary_source":"","published":"2026-06-22T14:17:52.640Z"},{"affected":"< 2.9.4","affected_versions_present":true,"cve_id":"CVE-2026-22219","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22219","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T15:53:20.438Z","patch_url":"https://www.zafran.io/resources/chainleak-critical-ai-framework-vulnerabilities-expose-data-enable-cloud-takeover","primary_source":"","published":"2026-01-19T23:15:08.897Z"},{"affected":"< 2.9.4","affected_versions_present":true,"cve_id":"CVE-2026-22218","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22218","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-14T15:53:19.759Z","patch_url":"https://www.zafran.io/resources/chainleak-critical-ai-framework-vulnerabilities-expose-data-enable-cloud-takeover","primary_source":"","published":"2026-01-19T23:14:52.969Z"},{"affected":"prior to 2.8.5","affected_versions_present":true,"cve_id":"CVE-2025-68492","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-68492","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-15T17:24:34.226Z","patch_url":"","primary_source":"","published":"2026-01-14T06:27:14.846Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Chainlit"}}
