Missing Authentication Vulnerability in Langchain-Chatchat by chatchat-space
CVE-2026-7844
Key Information:
- Vendor
Chatchat-space
- Status
- Vendor
- CVE Published:
- 5 May 2026
Badges
What is CVE-2026-7844?
A vulnerability has been identified in the Langchain-Chatchat product from chatchat-space, where the Compatible File Service fails to enforce proper authentication controls for specific functions. This oversight, affecting functions such as retrieving and deleting files, allows unauthorized users who have access to the local network to exploit the issue. As the exploit is now public, it poses a significant risk, particularly given the lack of response from the development team despite prior notifications of the vulnerability.
Affected Version(s)
Langchain-Chatchat 0.3.1.0
Langchain-Chatchat 0.3.1.1
Langchain-Chatchat 0.3.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
