Opening SecureFlowChainLeak: Chainlit File Read and SSRF to Cloud Exposure
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zafran aidefend-sf0015

ChainLeak: Chainlit File Read and SSRF to Cloud Exposure

  • AI Infrastructure
  • Data Exfiltration
  • Credential & Identity Theft

Zafran reported ChainLeak vulnerabilities in Chainlit that enabled arbitrary file read, cross-user prompt and response cache leakage, and SSRF through element URL handling, creating a path from AI framework helper APIs to secrets and cloud takeover risk.

Mapped threat techniques

Source