Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 20:20
Updated : 2026-09-16 13:42
NVD link : CVE-2026-82290
Mitre link : CVE-2026-82290
CVE.ORG link : CVE-2026-82290
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
