PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-7846 chatchat-space CVE debrief

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The impacted component is the OpenAI-Compatible File Upload API, specifically the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py. The vulnerability is due to improper handling of the argument file.filename, leading to a time-of-check time-of-use issue. Access to the local network is required for this attack to succeed, and a high level of complexity is needed. The exploitability is considered difficult.

Vendor
chatchat-space
Product
Langchain-Chatchat
CVSS
LOW 1.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-05
Original CVE updated
2026-07-24
Advisory published
2026-05-05
Advisory updated
2026-07-24

Who should care

Users of Langchain-Chatchat up to version 0.3.1.3 should be aware of this vulnerability and take necessary precautions to protect their systems, especially those with access to the local network.

Technical summary

The vulnerability is caused by improper handling of the file.filename argument in the OpenAI-Compatible File Upload API, leading to a time-of-check time-of-use issue. This occurs in the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File Upload API in chatchat-space Langchain-Chatchat up to 0.3.1.3. The attack requires access to the local network and has a high level of complexity, making exploitability difficult. Users should verify their deployments and prepare for patches or updates.

Defensive priority

Medium priority should be given to patching this vulnerability, especially for systems with local network access.

Recommended defensive actions

  • Apply patches or updates provided by the vendor as soon as they are available.
  • Restrict access to the OpenAI-Compatible File Upload API to only necessary personnel.
  • Monitor network traffic for suspicious activity related to the affected API.
  • Implement additional security measures such as input validation and error handling.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record was published on 2026-05-05T16:16:19.577Z and was last modified on 2026-07-24T08:10:00.150Z. The NVD entry is currently Deferred. Evidence is limited, and defenders should verify affected scope and vendor guidance. The vulnerability affects chatchat-space Langchain-Chatchat up to version 0.3.1.3, specifically the OpenAI-Compatible File Upload API.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-05T16:16:19.577Z and has not been modified since then. The NVD entry is currently Deferred.