PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7845 chatchat-space CVE debrief

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult.

Vendor
chatchat-space
Product
Langchain-Chatchat
CVSS
LOW 1.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-07-24
Advisory published
2026-05-05
Advisory updated
2026-07-24

Who should care

Users of Langchain-Chatchat up to 0.3.1.3, affected operators, platform administrators, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary precautions.

Technical summary

The vulnerability is caused by the use of a weak hash in the PIL.Image.tobytes function of the dialogue.py file in Langchain-Chatchat up to 0.3.1.3. The attack requires the attacker to be present on the local network and has high complexity. The exploitability is assessed as difficult. Users of Langchain-Chatchat up to 0.3.1.3 should review vendor guidance and consider compensating controls due to the difficulty of exploit and limited public evidence.

Defensive priority

Medium

Recommended defensive actions

  • Inventory and verify affected systems
  • Apply vendor patches or updates
  • Monitor for suspicious activity
  • Implement compensating controls
  • Review and follow vendor guidance
  • Track exceptions and retest remediated assets
  • Verify evidence of remediation

Evidence notes

The project was informed of the problem early through an issue report but has not responded yet. The exploit has been published and may be used. Evidence is limited to public sources and vendor notifications. Defenders should verify affected systems, review vendor guidance for updates, and monitor for suspicious activity. Affected operators, platform administrators, vulnerability management teams, and security teams should take necessary precautions.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T16:16:19.383Z and has not been modified since then.