Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Four unpatched CVEs in Langchain-Chatchat file APIs, exploits public

Four vulnerabilities (CVE-2026-7844 through CVE-2026-7847) were disclosed in chatchat-space Langchain-Chatchat up to version 0.3.1.3, including missing authentication on OpenAI-compatible file endpoints, a weak hash in the vision chat paste-image handler, a time-of-check time-of-use flaw in file upload, and predictable file IDs. Public exploits exist and the project had not responded to the reporter's issue reports.

Disclosed 5 May 2026 · Record updated 13 September 2026

Impact

Attackers with local network access can list, retrieve, overwrite or delete uploaded files without authentication, and predict file IDs, on Langchain-Chatchat installations up to 0.3.1.3; exploits are public and no vendor fix has been issued.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7844
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7845
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7846
  4. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-7847