CVE-2026-45018 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-45018 requires immediate attention.
· 6 min read
Executive Summary
CVE-2026-45018 is a critical remote code execution flaw in Chainlit affecting deployments that have MCP enabled. The issue is CVSS 9.8, but it is not known to be exploited in the wild and is not in CISA KEV at this time. The vulnerable path is reachable without authentication if your app exposes /mcp and has features.mcp.enabled = true.
The bug is in the stdio MCP command handling: attacker-controlled input can smuggle shell arguments through an allowlist check and trigger arbitrary command execution via npx -c. If you run Chainlit for internal tools, demos, or small-team apps, treat this as an emergency patch-and-audit item.
Immediate Action
- Upgrade Chainlit to 2.12.0 immediately once available in your package source. This is the fixed release.
- Disable MCP now by setting
features.mcp.enabled = falsein.chainlit/config.tomlif you cannot patch today. - Restrict exposure of
/mcpat the reverse proxy or firewall until you confirm the fix is deployed. - Check for unexpected process activity from the Chainlit host, especially
npx,sh,bash, or unknown child processes. - Review vendor guidance: Chainlit security advisory / release notes.
Affected Versions
chainlit>=2.4.0rc0, <2.12.0are vulnerable only iffeatures.mcp.enabled = true.- Deployments with MCP disabled by default since
v2.7.0are generally not affected unless MCP was explicitly turned on. chainlit@2.12.0is the patched release.- If you removed
allowed_executablesfrom config and still run a vulnerable version, risk increases because the validator may treatNoneas allow-all.
Resolution Guide
Python / pip
pip install --upgrade "chainlit==2.12.0"
# or, if you manage dependencies in requirements.txt:
# chainlit==2.12.0
pipx
pipx upgrade chainlit
# then verify the installed version is 2.12.0 or later
npm / yarn / pnpm
Chainlit is a Python package, so there is no direct npm/yarn/pnpm upgrade path for the server package. If you ship a JS frontend that talks to Chainlit, update the backend Python dependency instead.
Maven / Gradle
Not applicable for the Chainlit server package. Update the Python dependency in your deployment pipeline.
apt / yum
Not applicable unless you package Chainlit into a system image. Rebuild the image with the patched Python dependency.
Docker image tags
# Rebuild your image with the patched dependency
docker build -t yourapp:chainlit-2.12.0 .
# If you pin a base image or app image, update the tag in your Dockerfile:
# FROM yourorg/yourapp:chainlit-2.12.0
Config hardening
# .chainlit/config.toml
[features]
mcp.enabled = false
If you must keep MCP enabled after upgrading, ensure authentication is configured and keep the service behind a trusted proxy. Remove any legacy MCP config sections during migration to 2.12.0.
Minimal code/config fix example
# Before
[features.mcp]
enabled = true
# After: disable until patched
[features.mcp]
enabled = false
Detection & Verification
Check your installed version
python -c "import chainlit; print(chainlit.__version__)"
pip show chainlit
Check whether MCP is enabled
grep -nE 'mcp\.enabled|allowed_executables|features\.mcp' .chainlit/config.toml
Find vulnerable deployments
grep -RIn "allowed_executables\|mcp.enabled = true\|features.mcp" .
Dependency audit
pip-audit
uv pip audit
Verify the fix
# Confirm version is patched
python -c "import chainlit; print(chainlit.__version__)"
# Confirm MCP is disabled if you are using the emergency workaround
grep -n "mcp.enabled = false" .chainlit/config.toml
# Confirm /mcp is no longer reachable from an unauthenticated session
curl -i -X POST "http://TARGET:8000/mcp" -H 'Content-Type: application/json' -d '{}'
Operational check
Look for unexpected child processes spawned by the Chainlit worker. Any evidence of npx or shell execution from the app process should be treated as suspicious.
Risk and Impact
If exploited, an unauthenticated attacker can execute arbitrary commands on the server with the privileges of the Chainlit process. That can lead to full host compromise, secret theft, lateral movement, and persistence on small-team infrastructure that often lacks strong segmentation.
The blast radius is especially high for self-hosted demos, internal copilots, and developer tools exposed to the internet or a shared VPN. Even if you have not enabled MCP intentionally, verify your config before assuming you are safe.