The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in Langchain‑Chatchat Knowledge Base Creation and Upload | |
| Weaknesses | CWE-22 |
Thu, 01 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatchat-space
Chatchat-space langchain-chatchat |
|
| Vendors & Products |
Chatchat-space
Chatchat-space langchain-chatchat |
Thu, 01 Oct 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-10-01T21:35:55.173Z
Reserved: 2026-06-08T00:00:00.000Z
Link: CVE-2026-51883
No data.
Status : Received
Published: 2026-10-01T22:17:03.127
Modified: 2026-10-01T22:17:03.127
Link: CVE-2026-51883
No data.
OpenCVE Enrichment
Updated: 2026-10-01T23:30:14Z
Weaknesses