CVE-2026-45018 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-45018 requires immediate attention.

· 6 min read

Executive Summary

CVE-2026-45018 is a critical remote code execution flaw in Chainlit affecting deployments that have MCP enabled. The issue is CVSS 9.8, but it is not known to be exploited in the wild and is not in CISA KEV at this time. The vulnerable path is reachable without authentication if your app exposes /mcp and has features.mcp.enabled = true.

The bug is in the stdio MCP command handling: attacker-controlled input can smuggle shell arguments through an allowlist check and trigger arbitrary command execution via npx -c. If you run Chainlit for internal tools, demos, or small-team apps, treat this as an emergency patch-and-audit item.

Immediate Action

  • Upgrade Chainlit to 2.12.0 immediately once available in your package source. This is the fixed release.
  • Disable MCP now by setting features.mcp.enabled = false in .chainlit/config.toml if you cannot patch today.
  • Restrict exposure of /mcp at the reverse proxy or firewall until you confirm the fix is deployed.
  • Check for unexpected process activity from the Chainlit host, especially npx, sh, bash, or unknown child processes.
  • Review vendor guidance: Chainlit security advisory / release notes.

Affected Versions

  • chainlit>=2.4.0rc0, <2.12.0 are vulnerable only if features.mcp.enabled = true.
  • Deployments with MCP disabled by default since v2.7.0 are generally not affected unless MCP was explicitly turned on.
  • chainlit@2.12.0 is the patched release.
  • If you removed allowed_executables from config and still run a vulnerable version, risk increases because the validator may treat None as allow-all.

Resolution Guide

Python / pip

pip install --upgrade "chainlit==2.12.0"
# or, if you manage dependencies in requirements.txt:
# chainlit==2.12.0

pipx

pipx upgrade chainlit
# then verify the installed version is 2.12.0 or later

npm / yarn / pnpm

Chainlit is a Python package, so there is no direct npm/yarn/pnpm upgrade path for the server package. If you ship a JS frontend that talks to Chainlit, update the backend Python dependency instead.

Maven / Gradle

Not applicable for the Chainlit server package. Update the Python dependency in your deployment pipeline.

apt / yum

Not applicable unless you package Chainlit into a system image. Rebuild the image with the patched Python dependency.

Docker image tags

# Rebuild your image with the patched dependency
docker build -t yourapp:chainlit-2.12.0 .

# If you pin a base image or app image, update the tag in your Dockerfile:
# FROM yourorg/yourapp:chainlit-2.12.0

Config hardening

# .chainlit/config.toml
[features]
mcp.enabled = false

If you must keep MCP enabled after upgrading, ensure authentication is configured and keep the service behind a trusted proxy. Remove any legacy MCP config sections during migration to 2.12.0.

Minimal code/config fix example

# Before
[features.mcp]
enabled = true

# After: disable until patched
[features.mcp]
enabled = false

Detection & Verification

Check your installed version

python -c "import chainlit; print(chainlit.__version__)"
pip show chainlit

Check whether MCP is enabled

grep -nE 'mcp\.enabled|allowed_executables|features\.mcp' .chainlit/config.toml

Find vulnerable deployments

grep -RIn "allowed_executables\|mcp.enabled = true\|features.mcp" .

Dependency audit

pip-audit
uv pip audit

Verify the fix

# Confirm version is patched
python -c "import chainlit; print(chainlit.__version__)"

# Confirm MCP is disabled if you are using the emergency workaround
grep -n "mcp.enabled = false" .chainlit/config.toml

# Confirm /mcp is no longer reachable from an unauthenticated session
curl -i -X POST "http://TARGET:8000/mcp" -H 'Content-Type: application/json' -d '{}'

Operational check

Look for unexpected child processes spawned by the Chainlit worker. Any evidence of npx or shell execution from the app process should be treated as suspicious.

Risk and Impact

If exploited, an unauthenticated attacker can execute arbitrary commands on the server with the privileges of the Chainlit process. That can lead to full host compromise, secret theft, lateral movement, and persistence on small-team infrastructure that often lacks strong segmentation.

The blast radius is especially high for self-hosted demos, internal copilots, and developer tools exposed to the internet or a shared VPN. Even if you have not enabled MCP intentionally, verify your config before assuming you are safe.

Keep reading