Chainlit arbitrary file read and SSRF vulnerabilities (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Two Chainlit flaws, CVE-2026-22218 and CVE-2026-22219, can expose files, API keys, and cloud resources in AI application backends. One issue enables arbitrary file reads from servers handling Chainlit deployments, while the other enables SSRF in setups using a SQLAlchemy data layer. Chainlit 2.9.4 was released on 2025-12-24 to address the vulnerabilities. Users of affected systems are urged to update quickly because the backend weaknesses can reveal sensitive data even when the AI model itself is not compromised.
Related Happenings
Unauthenticated Moltbot instances expose configuration data and credentials
Data Leak
H score34
First: 28.01.2026 19:46
Last: 28.01.2026 19:46
Sources 1
About this happening:
Hundreds of unauthenticated Moltbot instances were found exposing configuration data, API keys, OAuth credentials, and private chat histories to unauthorized p...
Unauthenticated Moltbot instances expose configuration data and credentials
Data LeakAbout this happening: Hundreds of unauthenticated Moltbot instances were found exposing configuration data, API keys, OAuth credentials, and private chat histories to unauthorized p...
Visual Studio Code-delivered JavaScript backdoor
Malware Activity
H score29
First: 22.01.2026 00:00
Last: 22.01.2026 00:00
Sources 1
About this happening:
Jamf Threat Labs said North Korean threat actors behind Contagious Interview are using a new Visual Studio Code delivery path that lures developers into opening ma...
Visual Studio Code-delivered JavaScript backdoor
Malware ActivityAbout this happening: Jamf Threat Labs said North Korean threat actors behind Contagious Interview are using a new Visual Studio Code delivery path that lures developers into opening ma...
Publicly exposed training apps as recurring cloud-entry risk across security vendors
Trend
H score17
First: 21.01.2026 16:00
Last: 21.01.2026 16:00
Sources 1
About this happening:
Cybersecurity training apps left exposed on the public Internet are creating a recurring cloud-entry risk for security vendors and enterprise users. A scan identified...
Publicly exposed training apps as recurring cloud-entry risk across security vendors
TrendAbout this happening: Cybersecurity training apps left exposed on the public Internet are creating a recurring cloud-entry risk for security vendors and enterprise users. A scan identified...
DCRat delivered through PowerShell and MSBuild in PHALT#BLYX
Malware Activity
H score23
First: 06.01.2026 14:13
Last: 06.01.2026 14:13
Sources 1
About this happening:
SHADOW#REACTOR is a multi-stage Windows malware campaign that uses obfuscated VBS, PowerShell, wscript.exe, MSBuild.exe, and in-memory loaders to stealthil...
DCRat delivered through PowerShell and MSBuild in PHALT#BLYX
Malware ActivityAbout this happening: SHADOW#REACTOR is a multi-stage Windows malware campaign that uses obfuscated VBS, PowerShell, wscript.exe, MSBuild.exe, and in-memory loaders to stealthil...
Cloudflare WAF protections for React2Shell (CVE-2025-55182)
Advisory/Mitigation
H score36
First: 05.12.2025 17:12
Last: 05.12.2025 17:12
Sources 1
About this happening:
Cloudflare rolled out WAF protections for CVE-2025-55182 / React2Shell, a mitigation aimed at reducing unauthenticated RCE risk across React deployments. The actio...
Cloudflare WAF protections for React2Shell (CVE-2025-55182)
Advisory/MitigationAbout this happening: Cloudflare rolled out WAF protections for CVE-2025-55182 / React2Shell, a mitigation aimed at reducing unauthenticated RCE risk across React deployments. The actio...
Timeline
-
20.01.2026 18:30 1 articles · 5mo ago
Chainlit 2.9.4 patch for CVE-2026-22218 and CVE-2026-22219
Mitigation Patch UpdateChainlit released version 2.9.4 on 24 December, 2025 to address CVE-2026-22218 and CVE-2026-22219, which affected deployments using a SQLAlchemy data layer. Temporary web application firewall signatures were also published to reduce exposure until affected systems can be updated.
Show sources
- Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps — www.infosecurity-magazine.com — 20.01.2026 18:30
-
20.01.2026 18:30 2 articles · 5mo ago
Zafran Research disclosure of Chainlit arbitrary file read and SSRF flaws
Initial DisclosureZafran Research disclosed CVE-2026-22218 and CVE-2026-22219 in the Chainlit framework, showing that authenticated users could read arbitrary files from a Chainlit server and that SQLAlchemy-based deployments could be exposed to SSRF. The weaknesses could expose environment variables, local databases, cached prompts and responses, API keys, and cloud resources.
Show sources
- Chainlit Security Flaws Highlight Infrastructure Risks in AI Apps — www.infosecurity-magazine.com — 20.01.2026 18:30
- Chainlit AI framework bugs let hackers breach cloud environments — www.bleepingcomputer.com — 22.01.2026 00:37