PT-2026-104040 · Unknown · Langchain-Chatchat
CVE-2026-51882
·
Published
2026-10-01
·
Updated
2026-10-01
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Langchain-Chatchat version 0.3.0
Description
The OpenAI-compatible file upload endpoint
/v1/files is susceptible to path traversal, a condition where an attacker can access or write files outside the intended directory. By crafting malicious filenames, an attacker can write files to arbitrary locations outside the openai files directory. This issue has been exploited in real-world incidents.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Restrict access to the
/v1/files endpoint to minimize the risk of exploitation. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Langchain-Chatchat