Junglewise Threat Intelligence

CVE-2026-7846: chatchat-space Langchain-Chatchat TOCTOU in File Upload API

CVE-2026-7846 · Severity: low · CVSS 3.1 · Published 2026-05-05

Technologies: langchain-chatchat (PyPI), Chatchat-Space Langchain-Chatchat. Vendors: PyPI, Chatchat-Space.

Executive brief

Langchain-Chatchat, an application for building AI-powered chat interfaces, contains a flaw in how it handles file uploads. Because the system uses the original filename to determine where to store a file without checking if that file already exists, one user can accidentally or intentionally overwrite another user's uploaded files. This could lead to data loss or cause the AI to process incorrect information, such as an attacker-controlled image instead of a user's original document.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the OpenAI-Compatible File Upload API of Langchain-Chatchat. The vulnerable function in 'openai_routes.py' generates storage paths based on a deterministic combination of the upload date and the user-supplied filename. Because the server uses 'open(path, "wb")' without conflict detection or per-user isolation, a second upload with the same filename on the same day will silently overwrite the existing file. An attacker with local network access can exploit this to replace legitimate user uploads with malicious content, which the LLM may subsequently retrieve. As of the advisory date, the project has not yet released a patch.

Affected products

  • chatchat-space Langchain-Chatchat up to 0.3.1.3

Timeline

  • 2026-04-13: disclosed: Issue reported to the project maintainers via GitHub
  • 2026-05-05: advisory: Vulnerability published by VulDB and NVD

References

Related threats