CVE-2026-51884
Summary
| CVE | CVE-2026-51884 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-01 22:17:03 UTC |
| Updated | 2026-10-02 18:47:49 UTC |
| Description | The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory. |
Risk And Classification
Problem Types: n/a
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/chatchat-space/Langchain-Chatchat/issues/5466 | [email protected] | github.com | |
| gist.github.com/Ro1ME/da028c9ce13dd888e265b9bef01d6eca | [email protected] | gist.github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.