CVE-2026-51884
Description
AI Translation Available
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
https://gist.github.com/Ro1ME/da028c9ce13dd888e265b9bef01d6eca
https://github.com/chatchat-space/Langchain-Chatchat/issues/5466