CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ⬡ Vulnerabilities & CVEs May 05, 2026

CVE-2026-7846 | chatchat-space Langchain-Chatchat up to 0.3.1.3 OpenAI-Compatible File Upload API openai_routes.py files file.filename toctou (Issue 5463)

VulDB Archived May 05, 2026 ! Full text unavailable

A vulnerability categorized as problematic has been discovered in chatchat-space Langchain-Chatchat up to 0.3.1.3 . Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the component OpenAI-Compatible File Upload API . Such manipulation of the argument file.filename leads to time-of-check time-of-use. This vulnerability is traded as CVE-2026-7846 . Access to the local network is required for this attack to succeed. Furthermore, there is a

Full text unavailable — view original
✦ AI Summary · Claude Sonnet


    Full text unavailable.
    Open original ↗
    💬 Team Notes
    Article Info
    Source
    VulDB
    Category
    ⬡ Vulnerabilities & CVEs
    Published
    May 05, 2026
    Archived
    May 05, 2026
    Full Text
    ✗ Not available
    Open Original ↗