CVE-2025-68492 - CERT CVE
ID CVE-2025-68492
Sažetak Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
Reference
CVSS
Base: 4.2
Impact: 2.5
Exploitability:1.6
Pristup
VektorSloženostAutentikacija
NETWORK HIGH LOW
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 14-01-2026 - 16:25
Objavljeno 14-01-2026 - 07:16