VYPR

Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat

by Theopaid

CVEs (1)

  • CVE-2026-66750Jul 28, 2026
    risk 0.00cvss epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval…