{"data":{"id":"d0adb8ea-73c9-4e4c-bc4e-c8e25c2e823e","title":"CVE-2026-51882: The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An…","summary":"CVE-2026-51882 affects the OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0. The endpoint is vulnerable to path traversal, so an attacker can craft malicious filenames to write files to arbitrary locations outside the `openai_files` directory.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51882","publishedAt":"2026-10-01T22:17:03.003Z","cveId":"CVE-2026-51882","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedPackageRefs":null,"affectedVendors":[],"affectedVendorsRaw":["Langchain-Chatchat 0.3.0"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"Langchain-Chatchat path traversal in /v1/files file upload endpoint","headlinePromptVersion":"h1","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00415,"epssCheckedAt":"2026-10-10T12:08:26.106Z","kevDateAdded":null,"advisoryAliases":["GHSA-p52p-3gpf-v5f9"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:04.755Z","patchAvailable":null,"disclosureDate":"2026-10-01T22:17:03.003Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}