CVE-2026-7845
published 2026-05-05CVE-2026-7845: A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file…
PriorityP413low2.6CVSS 3.1
AVAACHPRLUINSUCNILAN
EPSS
0.14%
3.7th percentile
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chatchat-space | langchain-chatchat | — | — |
| chatchat-space | langchain-chatchat | — | — |
| chatchat-space | langchain-chatchat | — | — |
| chatchat-space | langchain-chatchat | — | — |
| chatchat-space | langchain-chatchat | 0 – 0.3.1.3 | — |
CVSS provenance
nvdv3.12.6LOWCVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
nvdv4.01.2LOWCVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.4LOWAV:A/AC:H/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wmvv-fhm6-w34x: A flaw has been found in chatchat-space Langchain-Chatchat up to 0
ghsa_unreviewed·2026-05-05
CVE-2026-7845 [LOW] CWE-327 GHSA-wmvv-fhm6-w34x: A flaw has been found in chatchat-space Langchain-Chatchat up to 0
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
GHSA
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
ghsa·2026-05-05
CVE-2026-7845 [LOW] CWE-327 Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
Langchain-Chatchat Uses a Broken or Risky Cryptographic Algorithm
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/3em0/cve_repo/blob/main/Langchain-Chatchat/Vuln-1-tobytes-Hash-Collision.mdhttps://github.com/chatchat-space/Langchain-Chatchat/https://github.com/chatchat-space/Langchain-Chatchat/issues/5462https://vuldb.com/submit/807794https://vuldb.com/vuln/361124https://vuldb.com/vuln/361124/ctihttps://github.com/chatchat-space/Langchain-Chatchat/issues/5462
2026-05-05
Published