Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. langchain-chatchat
  4. ›
  5. CVE-2026-7846

CVE-2026-7846: Langchain-Chatchat has a Race Condition in its OpenAI-Compatible File Upload API

May 5, 2026 (updated May 8, 2026)

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File Upload API. Such manipulation of the argument file.filename leads to time-of-check time-of-use. Access to the local network is required for this attack to succeed. The attack requires a high level of complexity. The exploitability is considered difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References

  • github.com/3em0/cve_repo/blob/main/Langchain-Chatchat/Vuln-2-Silent-File-Overwrite.md
  • github.com/advisories/GHSA-x229-w2j4-h748
  • github.com/chatchat-space/Langchain-Chatchat
  • github.com/chatchat-space/Langchain-Chatchat/issues/5463
  • nvd.nist.gov/vuln/detail/CVE-2026-7846
  • vuldb.com/submit/807795
  • vuldb.com/vuln/361125
  • vuldb.com/vuln/361125/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-7846 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 0.3.1.3

Solution

Unfortunately, there is no solution available yet.

Impact 2.6 LOW

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Source file

pypi/langchain-chatchat/CVE-2026-7846.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 00:19:18 +0000.