{"type":"bundle","id":"bundle--cd791201-3002-5a65-bf6b-f2bbb3785630","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--4ddbed52-8acb-5d9e-b1f4-95b9f3a6beab","created":"2026-09-20T19:29:23.747Z","modified":"2026-09-20T19:29:23.747Z","name":"Chainlit MCP stdio unauthenticated RCE","description":"Chainlit MCP stdio unauthenticated RCE. Upgrade to the patched release.","aliases":["CVE-2026-45018","CVE-2026-45019"],"first_seen":"2026-08-25T00:00:00.000Z","last_seen":"2026-08-25T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"NVD CVE-2026-45018","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45018"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-45018-chainlit-mcp-stdio-unauth-rce-2"},{"source_name":"CVE Record CVE-2026-45018","url":"https://www.cve.org/CVERecord?id=CVE-2026-45018"}]}]}