See how langchain-chatchat compares to other vendors in security performance
The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as ..\) into the knowledgebasename parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.
The OpenAI-compatible file upload endpoint /v1/files in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the openaifiles directory by crafting malicious filenames.