
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22219 is a Server-Side Request Forgery (SSRF) vulnerability in the Chainlit AI framework affecting all versions prior to 2.9.4. When configured with the SQLAlchemy data layer backend, the /project/element update flow accepts a user-controlled URL value in an Element object, which the server fetches via an outbound HTTP GET request without adequate validation. The vulnerability was published on January 19–20, 2026, and patched in Chainlit 2.9.4 released December 25, 2025. It carries a CVSS v3.1 base score of 7.7 (High) and a CVSS v4.0 base score of 8.3 (High) (NVD, Zafran).
The root cause is improper neutralization of user-supplied URL input in the SQLAlchemy data layer's element creation logic (CWE-918: Server-Side Request Forgery). When an authenticated user submits an Element update to the /project/element endpoint, the backend blindly issues an outbound HTTP GET request to the attacker-controlled URL and stores the response via the configured storage provider. This means the Chainlit server acts as an HTTP proxy, enabling requests to internal network services, cloud metadata endpoints (e.g., AWS IMDSv1 at 169.254.169.254), or other non-public resources. Exploitation requires only low-privilege authenticated access with no user interaction. A proof-of-concept is publicly documented by Zafran as part of the "ChainLeak" research (Zafran, VulnCheck Advisory).
An authenticated attacker can leverage this vulnerability to make arbitrary HTTP requests originating from the Chainlit server to internal network services and cloud metadata endpoints, effectively bypassing network perimeter controls. The primary impact is high confidentiality loss — retrieved responses (including cloud credentials, IAM tokens, and internal service data) are stored via the configured storage provider and accessible to the attacker. In cloud-hosted deployments, successful exploitation of cloud metadata endpoints (e.g., AWS IMDSv1) could yield temporary credentials enabling lateral movement and full cloud environment takeover. Integrity and availability are not directly impacted by this vulnerability (Zafran, BleepingComputer).
A proof-of-concept exploit is publicly available via Zafran's "ChainLeak" research report, which was added as an exploit reference in NVD on February 2, 2026 (Zafran, NVD). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The vulnerability is detected by Qualys (detection ID 5007132) and has an EPSS score of approximately 0.038% (0.000380), indicating low but non-zero probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
/project/element endpoint with a JSON body containing a user-controlled url field pointing to the desired internal target (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/ for AWS IMDSv1, or an internal service address).169.254.169.254) or unexpected internal RFC-1918 addresses; unusual HTTP traffic from the Chainlit server to internal services on non-standard ports./project/element POST requests with url fields pointing to internal or metadata addresses; storage provider logs showing new element objects created with content matching internal service responses.The primary remediation is to upgrade Chainlit to version 2.9.4 or later, which includes a fix described as "sanitization for custom thread element update" (PR #2737) (Chainlit Release). If immediate patching is not feasible, restrict outbound network access from the Chainlit server to block requests to cloud metadata endpoints (e.g., 169.254.169.254) and internal RFC-1918 address ranges using host-based firewall rules or network egress controls. Additionally, consider limiting authenticated user access to the /project/element update functionality until the patch is applied (Zafran, VulnCheck Advisory).
The vulnerability received significant media coverage under the "ChainLeak" campaign name coined by Zafran, which disclosed multiple Chainlit vulnerabilities simultaneously. Major outlets including The Hacker News, BleepingComputer, SecurityWeek, The Register, CSO Online, and Infosecurity Magazine covered the disclosure (The Hacker News, BleepingComputer, SecurityWeek). Security community discussion was active on Mastodon (infosec.exchange) and Reddit, with commentary highlighting the risk to AI-powered enterprise applications. DefectDojo published a blog post framing the ChainLeak findings as evidence of a broader trust problem with third-party AI frameworks (DefectDojo). The Hacker News also included the vulnerability in its weekly recap of critical CVEs for the week of January 13–19, 2026.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."