CVE 8.6 HIGH

CVE-2026-30617_CVE-2026-30617

8.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Description

LangChain-ChatChat 0.3.1 contains a remote code execution vulnerability in its MCP STDIO server configuration and execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and arguments. When the MCP server is started and MCP is enabled for agent execution, subsequent agent activity triggers execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the LangChain-ChatChat service.

AI Analysis

Remote code execution vulnerability in LangChain-ChatChat's MCP STDIO server configuration and execution handling

Basic Information

ID CVE-2026-30617
Source mitre
Published Apr 15, 2026 at 00:00
Modified Apr 15, 2026 at 18:00

Affected Product

Vendor LangChain
Product LangChain-ChatChat
Version 0.3.1
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor LangChain
Product LangChain-ChatChat
Version 0.3.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.