{"id":"CVE-2026-51883","title":"The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal","summary":"The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\\`) into the `knowledge_base_name` parameter to wri…","severity":"none","published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T22:17:03.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51883","references":[{"url":"https://gist.github.com/Ro1ME/30f5139a2920bf7075299a33eb1690f2","label":"cve@mitre.org"},{"url":"https://github.com/chatchat-space/Langchain-Chatchat/issues/5467","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T23:03:32.775Z","slug":"CVE-2026-51883","body":"## Overview\n\nThe knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\\`) into the `knowledge_base_name` parameter to write knowledge base content to arbitrary locations outside the configured knowledge base root directory.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}