CyberRota Analysis
AI-GeneratedThe temporary document upload endpoint in Langchain Chatchat 0.3.1 is susceptible to path traversal attacks, allowing an attacker to manipulate filenames to write files to arbitrary server locations. This vulnerability could lead to unauthorized access or modification of sensitive data on the server. Organizations using this version of Langchain should prioritize remediation to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.