Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19477 | Langchain-Chatchat has a Path Traversal vulnerability |
Github GHSA |
GHSA-qmgv-j263-qr33 | Langchain-Chatchat has a Path Traversal vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 16 Sep 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatchat-space
Chatchat-space langchain-chatchat |
|
| CPEs | cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chatchat-space
Chatchat-space langchain-chatchat |
Mon, 30 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 29 Jun 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. The manipulation of the argument flag leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Title | chatchat-space Langchain-Chatchat Backend upload_temp_docs path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-30T15:44:45.431Z
Reserved: 2025-06-28T10:37:51.109Z
Link: CVE-2025-6853
Updated: 2025-06-30T15:44:27.950Z
Status : Analyzed
Published: 2025-06-29T08:15:21.550
Modified: 2025-09-16T13:34:02.377
Link: CVE-2025-6853
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA