Описание
A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Ссылки
- ExploitIssue TrackingVendor Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.1 (включая)
cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 25%
0.00083
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 25%
0.00083
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-22