PatchSiren

chatchat-space CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW chatchat-space CVE published 2026-05-05

CVE-2026-7847

A vulnerability was found in Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component Uploaded File Handler. Performing a manipulation results in insufficiently random values. Access to the local network is required for this attack. The attack's complexity is rated as high. The exploita [truncated]

LOW chatchat-space CVE published 2026-05-05

CVE-2026-7846

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The impacted component is the OpenAI-Compatible File Upload API, specifically the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py. The vulnerability is due to improper handling of the argument file.filename, leading to a time-of-check time-of-use issue. Access to the local network [truncated]

LOW chatchat-space CVE published 2026-05-05

CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is consider [truncated]