CVE-2026-51882: Path Traversal

Published Oct 1, 2026
·
Updated

The OpenAI-compatible file upload endpoint /v1/files in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the openaifiles directory by crafting malicious filenames.

Affected Software

1 affected component
Langchain-Chatchat Langchain-Chatchat=0.3.0

Event History

Oct 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description

Frequently Asked Questions

1

Who can exploit this issue?

Any attacker able to submit uploads to the OpenAI-compatible /v1/files endpoint can attempt exploitation by supplying a crafted filename. The provided information does not state that authentication or special privileges are required.

2

What can an attacker do with a successful exploit?

A successful exploit allows files to be written to arbitrary locations outside the intended openai_files directory. The specific writable locations and resulting impact depend on the permissions of the process running Langchain-Chatchat.

3

How can I determine whether my deployment is affected?

Deployments running Langchain-Chatchat 0.3.0 with the OpenAI-compatible /v1/files upload endpoint exposed are affected according to the provided information. Review upload requests and stored filenames for traversal sequences that attempt to escape the openai_files directory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203