CVE Details
Basic Information
| Title | chatchat-space Langchain-Chatchat Backend upload_temp_docs path traversal |
|---|---|
| Type | cve |
| Published | 2025-06-29T07:31:05.027Z |
| Last Seen |
Product Information
| Vendor | chatchat-space |
|---|---|
| Product | Langchain-Chatchat |
| Version | 0.3.0 |
CVSS Information
| Base Score | 5.3 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P |
| Confidentiality Impact | |
| Integrity Impact | |
| Availability Impact |
AI Analysis
| AI Description | A path traversal vulnerability in the upload_temp_docs function of Langchain-Chatchat allows remote attackers to access unauthorized files by manipulating the ‘flag’ argument. |
|---|---|
| AI Severity | Medium |
| Vendor | chatchat-space |
| Product | Langchain-Chatchat |
| Affected Version | 0.3.0, 0.3.1 |
Affected Products
- chatchat-space Langchain-Chatchat 0.3.0
- chatchat-space Langchain-Chatchat 0.3.1
Additional Information
| CVE List | |
|---|---|
| CWE List | CWE-22 |
| Bulletin Family |
References
Description
A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.