Four unpatched CVEs in Langchain-Chatchat file APIs, exploits public
Four vulnerabilities (CVE-2026-7844 through CVE-2026-7847) were disclosed in chatchat-space Langchain-Chatchat up to version 0.3.1.3, including missing authentication on OpenAI-compatible file endpoints, a weak hash in the vision chat paste-image handler, a time-of-check time-of-use flaw in file upload, and predictable file IDs. Public exploits exist and the project had not responded to the reporter's issue reports.
Disclosed 5 May 2026 · Record updated 13 September 2026
Impact
Attackers with local network access can list, retrieve, overwrite or delete uploaded files without authentication, and predict file IDs, on Langchain-Chatchat installations up to 0.3.1.3; exploits are public and no vendor fix has been issued.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7844
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7845
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7846
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7847
