Retour à la veille

CVE-2026-51882

Publié : 1 octobre 2026
Modifié : 1 octobre 2026
Lien officiel NVD

Description détaillée

The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.

Références et Patchs