CVE-2026-66750

Summary

Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval route. Attackers can enumerate adjacent MongoDB ObjectIds derived from a known file ID to recover files uploaded by other users, as the GET /files/:id/:name route in app/controllers/files.js only enforces login authentication without consulting room membership or the Room.canJoin check.

Affected Software

VendorProductVersion RangeStatus
sdelementslets-chat0.3.0 <= 0.4.8affected
sdelementslets-chat55e8833974c83559ed2cbc12bc15febeb2466254 <= 617207ff3c0c0bf8e3c7a915bd9ec03f1dd8390caffected

Weaknesses

  • CWE-862: Missing Authorization

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

References