CVE-2026-51882 UNKNOWN

CVE-2026-51882

Published: 2026-10-01

Description

The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…