04:45
2026-08-31
dev.to
ai-safety
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
Chainlit 2.12.0 patches two critical vulnerabilities in its MCP endpoint: CVE-2026-45018, an unauthenticated remote code execution via the stdio transport, and CVE-2026-45019, an unauthenticated serveβ¦