CVE-2026-82290

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-28 20:20

Updated : 2026-09-16 13:42


NVD link : CVE-2026-82290

Mitre link : CVE-2026-82290

CVE.ORG link : CVE-2026-82290


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key