{"id":"CVE-2026-6855","aliases":["GHSA-pqmg-c2j8-fq92","PYSEC-2026-2521"],"title":"InstructLab vulnerable to Path Traversal","summary":"InstructLab vulnerable to Path Traversal","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","vendor":"instructlab","product":"instructlab","ecosystem":"pip","affected":["instructlab <= 0.26.1"],"published":"2026-04-22","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-pqmg-c2j8-fq92","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6855"},{"url":"https://access.redhat.com/security/cve/CVE-2026-6855"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2460013"},{"url":"https://github.com/instructlab/instructlab"}],"tags":["osv","pip"],"epss":0.00164,"epssPercentile":0.05992,"ingestedAt":"2026-07-13T18:58:01.658Z","slug":"CVE-2026-6855","body":"## Overview\n\nA flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.\n\n## Affected packages\n\n- `instructlab <= 0.26.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}