
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68492 is an authorization bypass through user-controlled key vulnerability in Chainlit, an open-source framework for building conversational AI applications. It affects all Chainlit versions prior to 2.8.5 and was disclosed on January 14, 2026, with the CVE record received from JPCERT/CC. An authenticated attacker can exploit this flaw to view other users' conversation threads or claim ownership of those threads. The vulnerability carries a CVSS v3.0 base score of 4.2 (Medium) as assessed by JPCERT/CC, and a CVSS v4.0 base score of 2.3 (Low) (GitHub Advisory, JVN).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the WebSocket connection handler in backend/chainlit/socket.py accepted a client-supplied threadId parameter during the connect event without verifying that the authenticated user was the actual owner of the specified thread. Because the thread ID was user-controlled and no server-side ownership check was performed, any logged-in user could supply an arbitrary thread ID to gain access to that thread's data. The fix, merged in pull request #2637, adds an explicit call to data_layer.get_thread_author(thread_id) and compares the result against the authenticated user's identifier before allowing the connection to proceed (GitHub PR #2637, Fix Commit).
Successful exploitation allows an authenticated attacker to read the full contents of conversation threads belonging to other users, potentially exposing sensitive information exchanged with AI assistants (e.g., proprietary data, personal information, or confidential queries). Additionally, the attacker may obtain ownership of those threads, enabling them to manipulate or delete conversation history. Availability is not impacted, and the scope is limited to the Chainlit application's data layer — lateral movement to underlying infrastructure is not directly facilitated by this vulnerability (GitHub Advisory, JVN).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-68492. The vulnerability requires the attacker to already have a valid login to the Chainlit application (low privileges required), and exploitation also depends on specific attack conditions being present (CVSS v4.0 Attack Requirements: Present). The EPSS score is approximately 0.027%, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been identified (GitHub Advisory, Feedly).
connect event, supply the target thread's ID in the auth payload (e.g., {"sessionId": "...", "threadId": "<victim-thread-id>", "clientType": "webapp", "chatProfile": null}).threadId values in rapid succession during the connect handshake.Authorization for the thread failed. errors (introduced in the patched version) for users attempting to access threads they do not own; on unpatched systems, absence of such errors despite cross-user thread access.Upgrade Chainlit to version 2.8.5 or later, which includes the authorization check added in commit 8f1153d that validates thread ownership during WebSocket connection establishment. No configuration-based workaround is available for unpatched versions; the only effective remediation is upgrading. Operators should also review access logs for anomalous cross-user thread access patterns prior to patching (GitHub Releases, GitHub Advisory).
The vulnerability was reported through JPCERT/CC and published on JVN (Japan Vulnerability Notes), indicating coordinated disclosure with the Chainlit maintainers. Community discussion on the GitHub pull request noted that the initial fix introduced a regression breaking Copilot mode, which was subsequently addressed in follow-up releases. No significant broader media coverage or notable researcher commentary beyond the GitHub thread has been identified (GitHub PR #2637, JVN).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."