Critical severity9.8NVD Advisory· Published Mar 6, 2026· Updated Jun 17, 2026
CVE-2026-28795
CVE-2026-28795
Description
OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through natural language conversations. Prior to version 0.2.2, the save_report tool in openchatbi/tool/save_report.py suffers from a critical path traversal vulnerability due to insufficient input sanitization of the file_format parameter. This issue has been patched in version 0.2.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
openchatbiPyPI | < 0.2.2 | 0.2.2 |
Affected products
3< 0.2.2+ 1 more
- (no CPE)range: < 0.2.2
- cpe:2.3:a:zhongyu09:openchatbi:*:*:*:*:*:*:*:*range: <0.2.2
Patches
Vulnerability mechanics
References
6- github.com/zhongyu09/openchatbi/commit/372a7e861da5159c3106d64d6f6edf8284db8c75nvdPatchWEB
- github.com/zhongyu09/openchatbi/pull/12nvdIssue TrackingPatchWEB
- github.com/zhongyu09/openchatbi/security/advisories/GHSA-vmwq-8g8c-jm79nvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-vmwq-8g8c-jm79ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-28795ghsaADVISORY
- github.com/zhongyu09/openchatbi/issues/10nvdIssue TrackingWEB
News mentions
0No linked articles in our index yet.