Authorization Flaw in SimpleChat Allows Low-Privileged User Exploitation
CVE-2026-105797
8.8HIGH
What is CVE-2026-105797?
In SimpleChat versions 0.261.003 and 0.261.027, an authorization ordering flaw allows authenticated low-privileged users to bypass necessary checks for ensuring proper action types. This enables attackers to execute arbitrary operating-system processes by manipulating stored personal actions, leading to exposure or modification of sensitive data. The vulnerability necessitates the use of personal plugins and appropriate governance settings to allow MCP actions, highlighting the importance of maintaining updated software to mitigate such risks. The issue has been addressed in version 0.261.031.
Affected Version(s)
simplechat < 0.261.031