CVE-2026-82290EPSS p25.2%

CVE-2026-82290CVE-2026-82290

Description

Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by supplying arbitrary feedback identifiers, corrupting human-rating data used for model evaluation.

Scoring

CVSS 5.3 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
EPSS0.34% probability of exploitation · percentile 25.2% · 2026-10-05T12:00:23Z
Last modified2026-09-16
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.