CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
Chainlit 2.12.0 patches two critical vulnerabilities in its MCP endpoint: CVE-2026-45018, an unauthenticated remote code execution via the stdio transport, and CVE-2026-45019, an unauthenticated serve…