lowCVSS 2.6Vulnerability

CVE-2026-7845

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

summary
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
severity
low
epss_score
0.0014
cvss_score
2.6
ghsa_published
2026-05-05T18:33:26Z
source_url
https://github.com/advisories/GHSA-wmvv-fhm6-w34x
ghsa_updated
2026-05-08T22:16:43Z
ghsa_id
GHSA-wmvv-fhm6-w34x
cve_id
CVE-2026-7845
cvss_vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
epss_percentile
0.03715

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/langchain-chatchat

AFFECTS (1)

[Software]pip/langchain-chatchat

HAS_WEAKNESS (1)

[Weakness]Use of a Broken or Risky Cryptographic Algorithm

Explore deeper with Ninja Signal's threat intelligence graph