---
id: CVE-2026-51884
title: >-
  The /knowledge_base/upload_temp_docs temporary document upload endpoint in
  Langchain Chatchat 0.3.1 is vulnerable to path traversal
summary: >-
  The /knowledge_base/upload_temp_docs temporary document upload endpoint in
  Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting
  malicious filenames, an attacker can write files to arbitrary locations on the
  server, bypas…
severity: none
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T22:17:03.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-51884'
references:
  - url: 'https://gist.github.com/Ro1ME/da028c9ce13dd888e265b9bef01d6eca'
    label: cve@mitre.org
  - url: 'https://github.com/chatchat-space/Langchain-Chatchat/issues/5466'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T23:03:32.775Z'
---

## Overview

The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
