---
id: CVE-2026-6855
title: >-
  instructlab: InstructLab: Path traversal allows arbitrary directory creation
  and file write (CVE-2026-6855)
summary: >-
  A flaw was found in InstructLab. A local attacker could exploit a path
  traversal vulnerability in the chat session handler by manipulating the
  `logs_dir` parameter. This allows the attacker to create new directories and
  write files to arbi…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
cwe: CWE-22
vendor: Red Hat
product: Red Hat Enterprise Linux AI (RHEL AI) 3
affected:
  - enterprise_linux_ai_rhel_ai 3
published: '2026-04-15'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T11:43:01+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6855.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6855.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-6855'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2460013'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-6855'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-6855'
  - url: 'https://github.com/instructlab/instructlab'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00164
epssPercentile: 0.05984
aliases:
  - GHSA-pqmg-c2j8-fq92
  - PYSEC-2026-2521
ecosystem: pip
ingestedAt: '2026-07-13T18:58:01.658Z'
---

## Overview

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat Enterprise Linux AI (RHEL AI) 3 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-6855.json)

**instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write** — rated Moderate by Red Hat. Released 2026-04-15, updated 2026-09-23.

Affected:

- Red Hat Enterprise Linux AI (RHEL AI) 3

No fix planned:

- Red Hat Enterprise Linux AI (RHEL AI) 3

## Remediation

Affected

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

## Package advisory (CVE-2026-6855)

Affected packages:

- `instructlab <= 0.26.1`

Source: https://osv.dev/vulnerability/GHSA-pqmg-c2j8-fq92
