PT-2025-45710 · Pypi · Langchain-Chatchat
Published
2025-06-29
·
Updated
2025-06-29
CVSS v3.1
5.5
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Langchain-Chatchat