---
id: CVE-2024-52787
aliases:
  - GHSA-3864-rp2m-2qfj
  - PYSEC-2026-1537
title: libre-chat Path Traversal vulnerability
summary: libre-chat Path Traversal vulnerability
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
vendor: libre-chat
product: libre-chat
ecosystem: pip
affected:
  - libre-chat <= 0.0.6
published: '2024-11-25'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-3864-rp2m-2qfj'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-52787'
  - url: 'https://github.com/vemonet/libre-chat/issues/10'
  - url: 'https://github.com/vemonet/libre-chat/pull/9'
  - url: >-
      https://github.com/vemonet/libre-chat/commit/dbb8e3400e5258112179783d74c9cc54310cb72b
  - url: 'https://gist.github.com/jxfzzzt/276a6e8cfbc54d2c2711bb51d8d3dff3'
  - url: 'https://github.com/vemonet/libre-chat'
tags:
  - osv
  - pip
epss: 0.00773
epssPercentile: 0.53829
ingestedAt: '2026-07-08T18:25:44.873Z'
---

## Overview

An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.

## Affected packages

- `libre-chat <= 0.0.6`

## Remediation

Refer to the advisory for the patched release.
