CVE-2026-51882EPSS p3.2%
CVE-2026-51882CVE-2026-51882
Description
The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` directory by crafting malicious filenames.
Scoring
| EPSS | 0.14% probability of exploitation · percentile 3.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |