UNKNOWN NVD
CVE-2026-51884
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filen
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
References
- https://gist.github.com/Ro1ME/da028c9ce13dd888e265b9bef01d6eca
- https://github.com/chatchat-space/Langchain-Chatchat/issues/5466
This unknown severity vulnerability was published on 2026-10-01 via NVD.
vulnfeed aggregates 9442 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.