CVE-2026-51884: Path Traversal
The /knowledgebase/uploadtempdocs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to be able to submit files to the /knowledge_base/upload_temp_docs endpoint and control the uploaded filename. Malicious path components in the filename can cause the server to write outside the intended temporary directory.
How can I determine whether my deployment is affected?
Deployments running Langchain Chatchat 0.3.1 should be treated as affected if the /knowledge_base/upload_temp_docs endpoint is available. Review upload handling and server file-write logs for filenames containing path traversal sequences or unexpected files written outside the temporary upload directory.
What can be done if updating is not immediately possible?
Restrict access to the temporary document upload endpoint to trusted users or disable it if it is not required. Enforce filename sanitization and canonical-path validation so that resolved upload paths remain within the designated temporary directory, and run the service with minimal filesystem permissions.