CVE-2026-45018 - Chainlit: Command injection via MCP stdio transport allows unauthenticated remote code execution
Brief
CVE ID : CVE-2026-45018
Published : Aug. 25, 2026, 8:16 p. m.
- 55 minutes ago
Description : Chainlit is a Python framework for building production-ready conversational AI applications. From 2.
- 0rc0 until 2.
- 0, Chainlit deployments with features. mcp. enabled set to true in . chainlit/config. toml expose the POST /mcp endpoint without requiring authentication. For stdio transport, the endpoint accepts a user-controlled fullCommand string.
The validate_mcp_command() function in backend/chainlit/mcp. py checks only the executable name against config. features. mcp. stdio. allowed_executables and passes unchecked arguments to StdioServerParameters in backend/chainlit/server. py. Because npx supports the -c argument, an attacker can execute arbitrary shell commands with the privileges of the Chainlit process.
