CVE-2026-7845
LOW
1,2
Source: [email protected]
Attack Vector: adjacent
Attack Complexity: high
Privileges Required: low
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
LOW
2,6
Source: [email protected]
Attack Vector: adjacent_network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
LOW
1,4
Source: [email protected]
Access Vector: adjacent_network
Access Complexity: high
Authentication: single
Confidentiality: none
Integrity: partial
Availability: none
Description
AI Translation Available
A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py of the component Vision Chat Paste Image Handler. This manipulation of the argument paste_image.image_data causes use of weak hash. The attacker needs to be present on the local network. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
327
Use of a Broken or Risky Cryptographic Algorithm
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Integrity
Accountability
Non-Repudiation
Potential Impacts:
Read Application Data
Modify Application Data
Hide Activities
Applicable Platforms
Languages:
Not Language-Specific, Verilog, VHDL
Technologies:
ICS/OT, Not Technology-Specific
328
Use of Weak Hash
DraftCommon Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies:
ICS/OT
https://github.com/3em0/cve_repo/blob/main/Langchain-Chatchat/Vuln-1-tobytes-Ha…
https://github.com/chatchat-space/Langchain-Chatchat/
https://github.com/chatchat-space/Langchain-Chatchat/issues/5462
https://vuldb.com/submit/807794
https://vuldb.com/vuln/361124
https://vuldb.com/vuln/361124/cti