CVE-2026-51882: Path Traversal
The OpenAI-compatible file upload endpoint /v1/files in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the openaifiles directory by crafting malicious filenames.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any attacker able to submit uploads to the OpenAI-compatible /v1/files endpoint can attempt exploitation by supplying a crafted filename. The provided information does not state that authentication or special privileges are required.
What can an attacker do with a successful exploit?
A successful exploit allows files to be written to arbitrary locations outside the intended openai_files directory. The specific writable locations and resulting impact depend on the permissions of the process running Langchain-Chatchat.
How can I determine whether my deployment is affected?
Deployments running Langchain-Chatchat 0.3.0 with the OpenAI-compatible /v1/files upload endpoint exposed are affected according to the provided information. Review upload requests and stored filenames for traversal sequences that attempt to escape the openai_files directory.