CVE-2026-82290: Chainlit Feedback Endpoints Missing Ownership Validation

Published Aug 28, 2026
·
Updated

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.

Affected Software

1 affected component
Chainlit<=2.12.0

Event History

Aug 28, 2026
CVE Published
via MITRE·04:19 PM
Data Sourced
via MITRE·04:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be authenticated and able to send requests to the affected PUT or DELETE feedback endpoints. They also need a feedback identifier belonging to another user; exploitation has high attack complexity.

2

What is the impact of a successful exploit?

An attacker can modify or delete feedback records created by other users. This can corrupt the human-rating data used for model evaluation, affecting integrity but not confidentiality or availability.

3

Are default deployments affected?

The available data identifies Chainlit through version 2.12.0 as affected, but does not state whether the vulnerable feedback endpoints are enabled or reachable in a default deployment.

4

How can teams check for possible exploitation?

Review feedback update and deletion activity for records changed or removed by accounts other than their owners. The issue concerns PUT and DELETE requests where arbitrary feedback identifiers were supplied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203