PatchSiren cyber security CVE debrief
CVE-2026-7845 chatchat-space CVE debrief
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult.
- Vendor
- chatchat-space
- Product
- Langchain-Chatchat
- CVSS
- LOW 1.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-05
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-05
- Advisory updated
- 2026-07-24
Who should care
Users of Langchain-Chatchat up to 0.3.1.3, affected operators, platform administrators, vulnerability management teams, and security teams should be aware of this vulnerability and take necessary precautions.
Technical summary
The vulnerability is caused by the use of a weak hash in the PIL.Image.tobytes function of the dialogue.py file in Langchain-Chatchat up to 0.3.1.3. The attack requires the attacker to be present on the local network and has high complexity. The exploitability is assessed as difficult. Users of Langchain-Chatchat up to 0.3.1.3 should review vendor guidance and consider compensating controls due to the difficulty of exploit and limited public evidence.
Defensive priority
Medium
Recommended defensive actions
- Inventory and verify affected systems
- Apply vendor patches or updates
- Monitor for suspicious activity
- Implement compensating controls
- Review and follow vendor guidance
- Track exceptions and retest remediated assets
- Verify evidence of remediation
Evidence notes
The project was informed of the problem early through an issue report but has not responded yet. The exploit has been published and may be used. Evidence is limited to public sources and vendor notifications. Defenders should verify affected systems, review vendor guidance for updates, and monitor for suspicious activity. Affected operators, platform administrators, vulnerability management teams, and security teams should take necessary precautions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-7845 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-7845
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-7845 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-7845
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/3em0/cve_repo/blob/main/Langchain-Chatchat/Vuln-1-tobytes-Hash-Collision.md
-
Source reference
Unverified legacy reference
URL: https://github.com/chatchat-space/Langchain-Chatchat/
-
Source reference
Unverified legacy reference
URL: https://github.com/chatchat-space/Langchain-Chatchat/issues/5462
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/807794
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/361124
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/361124/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.