Junglewise Threat Intelligence

CVE-2026-66749: sdelements Let's Chat null dereference in room lookup

CVE-2026-66749 · Severity: medium · CVSS 6.5 · Published 2026-07-28

Technologies: Sdelements Let's Chat.

Executive brief

Let's Chat, a self-hosted chat application for small teams, is vulnerable to a flaw that allows any logged-in user to crash the entire server. By sending a specially crafted request for a non-existent chat room, an attacker can force the application to shut down. This results in a complete denial of service, preventing all users from communicating until the server is manually restarted.

Technical details

A NULL pointer dereference (CWE-476) exists in Let's Chat versions 0.4.0 through 0.4.8. The vulnerability occurs when the application processes a 'GET /messages' request with a 'room' parameter consisting of a valid 24-character hex string that does not exist in the database. Because the application fails to verify if the room lookup returned a valid object before calling methods on it, an uncaught TypeError is thrown within an asynchronous Mongoose callback. Since Express does not catch exceptions in asynchronous callbacks, the error propagates to the Node.js runtime, causing the server process to terminate. This flaw is also reachable via the socket.io interface.

Affected products

  • sdelements Let's Chat 0.4.0 through 0.4.8

Timeline

  • 2026-07-28: advisory: NVD publication date

References