CVE-2026-51884

Published: Ott 02, 2026 Last Modified: Ott 02, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.

https://gist.github.com/Ro1ME/da028c9ce13dd888e265b9bef01d6eca
https://github.com/chatchat-space/Langchain-Chatchat/issues/5466