CVE-2026-22219 | Chainlit up to 2.9.3 HTTP GET Request /project/element url server-side request forgery
A vulnerability marked as critical has been reported in Chainlit up to 2.9.3. The affected element is an unknown function of the file /project/element of the component HTTP GET Request Handler. Performing a manipulation of the argument url results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-22219. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.