What happened
NVD published three path-traversal CVEs for Langchain-Chatchat on 2026-10-01 (CVE-2026-51882 in /v1/files, CVE-2026-51883 in knowledge-base creation, CVE-2026-51884 in upload_temp_docs), all unrated and awaiting vendor fix. An attacker crafts filenames to write outside the intended directories.
Why it matters
Langchain-Chatchat is widely used for RAG deployments; arbitrary file write on the model-serving host is a stepping stone to RCE in a RAG deployment, though these are unrated, vendor-unfixed, and require authenticated use of the specific endpoints (hence Tier C).
Attack vector
Crafted malicious filenames in file-upload calls to /v1/files (path traversal outside openai_files) and to knowledge_base_name / upload_temp_docs endpoints escape the intended directory, writing files to arbitrary locations on the server.
Affected systems
Langchain-Chatchat 0.3.0, 0.3.1
Mitigation
Apply upstream fixes once available (chatchat-space/Langchain-Chatchat issue #5468); restrict access to the OpenAI-compatible and KB upload endpoints.