Zafran Security A.I CyberSecurity Scoring
Zafran Security
Company Information
Website:https://www.zafran.io/
Employees number:146
Number of followers:10,708
NAICS:541514
Industry Type:Computer and Network Security
Homepage:zafran.io
Zafran Security Risk Score (AI oriented)
Between 750 and 799
Zafran SecurityComputer and Network Security
Updated:
31/03/2026
31/03/2026
751/1000
Fair
Baa
Zafran Security Global Score (TPRM)
xxxx
Zafran SecurityComputer and Network Security
Score locked

Zafran SecurityFair
Current Score
751Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751
MAY 2026
751
APRIL 2026
751
MARCH 2026
751
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
751
Vulnerability
23 Nov 2025 • Zafran Security
Chainlit: Chainlit AI framework bugs let hackers breach cloud environments
Critical Vulnerabilities in Chainlit Framework Expose AI Systems to Data Theft and Server Compromise
750
CRITICAL-1
ZAF1769037749
Critical Vulnerabilities in Chainlit Framework Expose AI Systems to Data Theft and Server Compromise
Researchers at Zafran Labs have uncovered two high-severity vulnerabilities in Chainlit, a widely used open-source framework for building conversational AI applications. The flaws, dubbed ChainLeak, enable attackers to read arbitrary files on affected servers and extract sensitive data without requiring user interaction.
The vulnerabilities CVE-2026-22218 (arbitrary file read) and CVE-2026-22219 (server-side request forgery, or SSRF) pose significant risks to internet-facing AI systems deployed across enterprises, academic institutions, and production environments. Chainlit, which averages 700,000 monthly downloads on PyPI and over 5 million annual downloads, provides a web-based UI, authentication tools, and cloud deployment support, making it a common choice for AI-driven applications.
CVE-2026-22218 allows attackers to exploit the `/project/element` endpoint by submitting a malicious element with a manipulated `path` field, forcing the server to copy and expose any accessible file including API keys, cloud credentials, configuration files, and authentication secrets.
CVE-2026-22219, affecting deployments using SQLAlchemy, enables SSRF attacks by tricking the server into making unauthorized outbound requests to internal services. Attackers can then retrieve the fetched data, potentially accessing restricted internal IPs and services. Zafran Labs demonstrated that combining both flaws could lead to full-system compromise and lateral movement in cloud environments.
The vulnerabilities were reported to Chainlit maintainers on November 23, 2025, with an acknowledgment received on December 9, 2025. A patch was released on December 24, 2025, in Chainlit version 2.9.4, with subsequent updates (including 2.9.6) addressing the issues. Organizations using affected versions are advised to upgrade immediately.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
OCTOBER 2025
751
SEPTEMBER 2025
751
AUGUST 2025
751
JULY 2025
751
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Zafran Security ??
What was Zafran Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Zafran Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Zafran Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Zafran Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Zafran Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Zafran Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Zafran Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Zafran Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Zafran Security's A.I Rankiteo Cyber Score in September 2025 ??
What was Zafran Security's A.I Rankiteo Cyber Score in August 2025 ??
What was Zafran Security's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Zafran Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Zafran Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Zafran Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?