OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-51884

CRITICAL · CVSS 9.8 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The temporary document upload endpoint in Langchain Chatchat 0.3.1 is susceptible to path traversal attacks, allowing an attacker to manipulate filenames to write files to arbitrary server locations. This vulnerability could lead to unauthorized access or modification of sensitive data on the server. Organizations using this version of Langchain should prioritize remediation to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51884
Severity
CRITICAL
CVSS
9.8
EPSS
0.15%

Original NVD Description

The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to arbitrary locations on the server, bypassing the intended restrictions on the temporary directory.