๐Ÿ” CVE Alert

CVE-2026-66749

MEDIUM 6.5

Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages request causing an uncaught TypeError in an asynchronous Mongoose callback that terminates the Node.js server process, with the same defect reachable through multiple code paths including the socket.io interface.

CWE CWE-476
Vendor sdelements
Product lets-chat
Published Jul 28, 2026
Last Updated Jul 28, 2026
Stay Ahead of the Next One

Get instant alerts for sdelements lets-chat

Be the first to know when new medium vulnerabilities affecting sdelements lets-chat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

sdelements / lets-chat
0.4.0 โ‰ค 0.4.8 84981a6d2534445c00ea4e095c934e46943c0b1d โ‰ค 617207ff3c0c0bf8e3c7a915bd9ec03f1dd8390c

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/theopaid/Unchecked-Room-Lookup-Leads-to-Server-Crash-Let-s-Chat- vulncheck.com: https://www.vulncheck.com/advisories/let-s-chat-denial-of-service-via-null-dereference-in-room-lookup

Credits

Theodosis Paidakis