The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in Langchain‑Chatchat Knowledge Base Creation and Upload | |
| Weaknesses | CWE-22 |
Thu, 01 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatchat-space
Chatchat-space langchain-chatchat |
|
| Vendors & Products |
Chatchat-space
Chatchat-space langchain-chatchat |
Thu, 01 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-01T21:35:55.173Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51883
No data.
Status : Deferred
Published: 2026-10-01T22:17:03.127
Modified: 2026-10-02T18:47:49.947
Link: CVE-2026-51883
No data.
OpenCVE Enrichment
Updated: 2026-10-01T23:30:14Z
Weaknesses
No weakness.