Описание
A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Ссылки
- ExploitIssue Tracking
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- ExploitIssue Tracking
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.1 (включая)
cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00095
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 6.3
github
7 месяцев назад
Langchain-Chatchat has a Path Traversal vulnerability
EPSS
Процентиль: 27%
0.00095
Низкий
6.3 Medium
CVSS3
9.8 Critical
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-22