Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
Unauthenticated users can run arbitrary shell commands on exposed Chainlit servers when MCP stdio is enabled.

1 CRIT · 7 HIGH · 4 MED · THREAT RED · 12 items · Generated in 259s
Unauthenticated users can run arbitrary shell commands on exposed Chainlit servers when MCP stdio is enabled.
A malicious site can send commands to the local MCP server without auth by spoofing an allowed Origin prefix.
Unauthenticated SSRF can reach internal services and cloud metadata when MCP is enabled.
Low-complexity operator injection can expose other tenants' data through affected MongoDB query filters.
A malicious MCP client or prompt-injected agent can write attacker-controlled files to arbitrary paths and potentially execute code.
Unauthenticated users can read arbitrary server files via the Gradio interface, exposing secrets, keys, and sensitive data.
Unauthenticated input can trigger OS command execution, letting attackers fully compromise systems running the package.
Anyone can send fake webhook requests and delete or corrupt user vector data when the secret is left unset.
It highlights common failures like weak defaults, fake checks, and off-task agents that can turn routine systems into attack paths.
Autonomous agents can act with broad privileges, so weak identity controls can turn one mistake into wider access abuse.
Easier deployment without safer defaults can increase insecure AI agent setups and user-driven exposure.
Stolen sessions can let attackers access Claude accounts and exposed data without needing passwords.