UNKNOWN NVD
CVE-2026-51883
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traver
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.
References
- https://gist.github.com/Ro1ME/30f5139a2920bf7075299a33eb1690f2
- https://github.com/chatchat-space/Langchain-Chatchat/issues/5467
This unknown severity vulnerability was published on 2026-10-01 via NVD.
vulnfeed aggregates 9442 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.