VYPR
Unrated severityNVD Advisory· Published Oct 1, 2026

CVE-2026-51883

CVE-2026-51883

Description

The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as ..\) into the knowledge_base_name parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.