PT-2026-34328 · Unknown · Instructlab

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-6855

CVSS v3.1

7.1

High

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions InstructLab (affected versions not specified)
Description A path traversal flaw exists in the chat session handler. A local attacker can manipulate the logs dir parameter to create new directories and write files to arbitrary locations on the system, which may result in unauthorized data modification or disclosure. Path traversal is a technique that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables or parameters that are used to build a file path.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-6855

Affected Products

Instructlab