High severityNVD Advisory· Published Mar 6, 2026· Updated Mar 9, 2026
OpenChatBI: Critical Path Traversal Vulnerability in save_report Tool of OpenChatBI
CVE-2026-28795
Description
OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through natural language conversations. Prior to version 0.2.2, the save_report tool in openchatbi/tool/save_report.py suffers from a critical path traversal vulnerability due to insufficient input sanitization of the file_format parameter. This issue has been patched in version 0.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openchatbiPyPI | < 0.2.2 | 0.2.2 |
Affected products
2- Range: < 0.2.2
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-vmwq-8g8c-jm79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-28795ghsaADVISORY
- github.com/zhongyu09/openchatbi/commit/372a7e861da5159c3106d64d6f6edf8284db8c75ghsax_refsource_MISCWEB
- github.com/zhongyu09/openchatbi/issues/10ghsax_refsource_MISCWEB
- github.com/zhongyu09/openchatbi/pull/12ghsax_refsource_MISCWEB
- github.com/zhongyu09/openchatbi/security/advisories/GHSA-vmwq-8g8c-jm79ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.