A vulnerability identified as problematic has been detected in sdelements Lets Chat up to 0.4.8. The affected element is an unknown function of the component Mongoose Callback Handler. This manipulation of the argument room causes null pointer dereference. This vulnerability only affects products that are no longer supported by the maintainer.

This vulnerability is tracked as CVE-2026-66749. The attack is possible to be carried out remotely. No exploit exists.

Applying a patch is the recommended action to fix this issue.