chatchat-space Langchain-Chatchat Backend upload_temp_docs path traversal

CVE Details

Basic Information

Title chatchat-space Langchain-Chatchat Backend upload_temp_docs path traversal
Type cve
Published 2025-06-29T07:31:05.027Z
Last Seen

Product Information

Vendor chatchat-space
Product Langchain-Chatchat
Version 0.3.0

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Confidentiality Impact
Integrity Impact
Availability Impact

AI Analysis

AI Description A path traversal vulnerability in the upload_temp_docs function of Langchain-Chatchat allows remote attackers to access unauthorized files by manipulating the ‘flag’ argument.
AI Severity Medium
Vendor chatchat-space
Product Langchain-Chatchat
Affected Version 0.3.0, 0.3.1

Affected Products

  • chatchat-space Langchain-Chatchat 0.3.0
  • chatchat-space Langchain-Chatchat 0.3.1

Additional Information

CVE List
CWE List CWE-22
Bulletin Family

Description

A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.