CVE-2026-82290: chainlit: Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints | Rapid7 Vulnerability Database