Описание
A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used.
Ссылки
- ExploitIssue TrackingVendor Advisory
- Permissions RequiredVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 0.3.1 (включая)
cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:*
EPSS
Процентиль: 27%
0.00095
Низкий
5.5 Medium
CVSS3
8.8 High
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
EPSS
Процентиль: 27%
0.00095
Низкий
5.5 Medium
CVSS3
8.8 High
CVSS3
5.2 Medium
CVSS2
Дефекты
CWE-22