Vulnerability  ·  2026-10-03

Langchain-Chatchat: path-traversal cluster allows arbitrary file writes via OpenAI-compatible and knowledge-base upload endpoints (CVE-2026-51882/51883/51884)

VulnerabilityMedium impactGlobalCVE-2026-51882
NVD published three path-traversal CVEs for Langchain-Chatchat on 2026-10-01 (CVE-2026-51882 in /v1/files, CVE-2026-51883 in knowledge-base creation, CVE-2026-51884 in upload_temp_docs), all unrated and awaiting vendor fix. An attacker crafts filenames to write outside the intended directories.
Langchain-Chatchat is widely used for RAG deployments; arbitrary file write on the model-serving host is a stepping stone to RCE in a RAG deployment, though these are unrated, vendor-unfixed, and require authenticated use of the specific endpoints (hence Tier C).
Crafted malicious filenames in file-upload calls to /v1/files (path traversal outside openai_files) and to knowledge_base_name / upload_temp_docs endpoints escape the intended directory, writing files to arbitrary locations on the server.
Langchain-Chatchat 0.3.0, 0.3.1
Apply upstream fixes once available (chatchat-space/Langchain-Chatchat issue #5468); restrict access to the OpenAI-compatible and KB upload endpoints.
NVD CVE-2026-51882NVD CVE-2026-51883NVD CVE-2026-51884
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →