Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Zafran Security

Zafran Security Vendor Cyber Rating & Cyber Score

zafran.io

Zafran is an AI-native exposure management platform that eliminates the manual toil of vulnerability management by cutting through noise, revealing what is truly exploitable, and automating mitigation and remediation using the security controls teams already have. We are a team of practitioners and builders shaped by high-stakes security moments, where clarity and speed mattered, and manual processes came at a real cost. We’re on a mission to proactively stop the exploitation of vulnerabilities, everywhere.


Zafran Security A.I CyberSecurity Scoring

Zafran Security
Company Information
Website:https://www.zafran.io/
Employees number:146
Number of followers:10,708
NAICS:541514
Industry Type:Computer and Network Security
Homepage:zafran.io
Zafran Security Risk Score (AI oriented)
Between 750 and 799
logo
Zafran SecurityComputer and Network Security
Updated:
31/03/2026
751/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Zafran Security Global Score (TPRM)
xxxx
logo
Zafran SecurityComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Zafran Security
Zafran SecurityFair
Current Score
751Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751Before Incident
MAY 2026
751Before Incident
APRIL 2026
751Before Incident
MARCH 2026
751Before Incident
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
751Before Incident
Vulnerability
23 Nov 2025Zafran Security
Chainlit: Chainlit AI framework bugs let hackers breach cloud environments

Critical Vulnerabilities in Chainlit Framework Expose AI Systems to Data Theft and Server Compromise

750After Incident
CRITICAL-1
ZAF1769037749
Critical Vulnerabilities in Chainlit Framework Expose AI Systems to Data Theft and Server Compromise Researchers at Zafran Labs have uncovered two high-severity vulnerabilities in Chainlit, a widely used open-source framework for building conversational AI applications. The flaws, dubbed ChainLeak, enable attackers to read arbitrary files on affected servers and extract sensitive data without requiring user interaction. The vulnerabilities CVE-2026-22218 (arbitrary file read) and CVE-2026-22219 (server-side request forgery, or SSRF) pose significant risks to internet-facing AI systems deployed across enterprises, academic institutions, and production environments. Chainlit, which averages 700,000 monthly downloads on PyPI and over 5 million annual downloads, provides a web-based UI, authentication tools, and cloud deployment support, making it a common choice for AI-driven applications. CVE-2026-22218 allows attackers to exploit the `/project/element` endpoint by submitting a malicious element with a manipulated `path` field, forcing the server to copy and expose any accessible file including API keys, cloud credentials, configuration files, and authentication secrets. CVE-2026-22219, affecting deployments using SQLAlchemy, enables SSRF attacks by tricking the server into making unauthorized outbound requests to internal services. Attackers can then retrieve the fetched data, potentially accessing restricted internal IPs and services. Zafran Labs demonstrated that combining both flaws could lead to full-system compromise and lateral movement in cloud environments. The vulnerabilities were reported to Chainlit maintainers on November 23, 2025, with an acknowledgment received on December 9, 2025. A patch was released on December 24, 2025, in Chainlit version 2.9.4, with subsequent updates (including 2.9.6) addressing the issues. Organizations using affected versions are advised to upgrade immediately.
INCIDENT DETAILS -
TYPE
Vulnerability ExploitationData TheftServer-Side Request Forgery (SSRF)
IMPACT
API keysCloud credentialsConfiguration filesAuthentication secretsInternet-facing AI systemsCloud environmentsPotential full-system compromiseLateral movement in cloud environments
DATA BREACH
API keysCloud credentialsConfiguration filesAuthentication secretsSensitivity Of Data: High
OCTOBER 2025
751Before Incident
SEPTEMBER 2025
751Before Incident
AUGUST 2025
751Before Incident
JULY 2025
751Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Zafran Security ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Zafran Security's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Zafran Security's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Zafran Security ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Zafran Security's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?