PT-2026-37081 · Unknown · Langchain-Chatchat

Dem00

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-7844

CVSS v3.1

6.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Langchain-Chatchat versions prior to 0.3.1.4
Description A missing authentication issue exists in the Compatible File Service component within the file libs/chatchat-server/chatchat/server/api server/openai routes.py. This flaw affects the functions files(), list files(), retrieve file(), retrieve file content(), and delete file(). An attacker with local network access can exploit this to perform unauthorized actions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the functions files(), list files(), retrieve file(), retrieve file content(), and delete file() within the Compatible File Service to minimize the risk of exploitation.

Exploit

Improper Authentication

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7844

Affected Products

Langchain-Chatchat