Loading market data...
← Back to CVE feed

CVE-2026-82290

MEDIUM CVSS 5.3 View on NVD ↗

Description

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Published: Aug 28, 2026 20:20 UTC Modified: Aug 28, 2026 20:20 UTC