CVE-2025-68492: Medium severity npm/chainlit vulnerability
Published Jan 14, 2026
·Updated
Chainlit versions prior to 2.8.5 contain an authorization bypass through user-controlled key vulnerability. If this vulnerability is exploited, threads may be viewed or thread ownership may be obtained by an attacker who can log in to the product.
Affected Software
2 affected componentsFixes available
npm/chainlit<2.8.5
pip/chainlit<2.8.5
2.8.5
Event History
Jan 14, 2026
CVE Published
via MITRE·06:27 AM
Data Sourced
via MITRE·06:27 AM
DescriptionSeverity
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·09:31 AM
Data Sourced
via GitHub·09:31 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68492?
The severity of CVE-2025-68492 is considered high due to the potential for an attacker to bypass authorization and manipulate thread ownership.
2
How do I fix CVE-2025-68492?
To fix CVE-2025-68492, upgrade Chainlit to version 2.8.5 or later.
3
What type of vulnerability is CVE-2025-68492?
CVE-2025-68492 is an authorization bypass vulnerability that can be exploited through user-controlled keys.
4
What can an attacker do if they exploit CVE-2025-68492?
If exploited, an attacker can view threads or obtain ownership of those threads in the application.
5
Which versions of Chainlit are affected by CVE-2025-68492?
Chainlit versions prior to 2.8.5 are affected by CVE-2025-68492.