THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w3fx-mc44-mf6j (critical) — Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

[GHSA] GHSA-w3fx-mc44-mf6j (critical) — Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

highgithub_advisoriesPublished 2026-08-25

GHSA-w3fx-mc44-mf6j Severity: critical CVE: CVE-2026-45018

Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

### Am I affected?

Only if your deployment sets `features.mcp.enabled = true` in `.chainlit/config.toml`. **MCP has been disabled by default since v2.7.0**, so most Chainlit deployments are not affected. No authentication is required

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w3fx-mc44-mf6j