Database/AI/ML frameworks & serving
Langchain-Chatchat: arbitrary file write outside the upload and knowledge-base directories
Impact
Three path traversal flaws let a user of the RAG service write files to arbitrary locations the server process can reach: the OpenAI-compatible /v1/files endpoint (0.3.0), the knowledge_base_name parameter on knowledge-base creation and document upload (0.3.0, 0.3.1), and /knowledge_base/upload_temp_docs (0.3.1). Arbitrary file write as the service account is a plausible path to code execution - overwriting application code, a startup script or an SSH authorized_keys file - so on a GPU node this turns access to a retrieval endpoint into control of whatever that container or host account holds, including the credentials and model files mounted beside it. This entry covers CVE-2026-51882, CVE-2026-51883 and CVE-2026-51884: three endpoints, one flaw class in one component, filed together by one reporter with no vendor advisory and no fixed release. Reports are researcher gists and GitHub issues; no CVSS score was assigned.
Who can reach it
Anyone who can reach the Chatchat HTTP API and submit an upload or create a knowledge base. The reports do not establish that authentication is required, and these deployments are commonly run without it, so treat any network-reachable instance as exposed.
What to do
No fixed version exists in the records as published - the issues are open upstream. Mitigate: take the service off any shared or tenant-reachable network, put authentication and a reverse proxy in front of it, run it as an unprivileged user in a container with a read-only root filesystem, and keep the upload and knowledge-base paths on a dedicated writable volume. Mitigation is configuration and a redeploy of the service; no node maintenance is involved.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- llama.cpp: a crafted GGUF file trips a reachable assertion and aborts the process loading itCVE-2026-52131 · llama.cpp (gguf_reader::read GGUF model file parser)Unscored
- llama.cpp server: negative top_n on /rerank drives an unbounded allocation and denial of serviceCVE-2026-52132 · llama.cpp server /rerank endpoint (top_n handling under --reranking)Unscored
- Hugging Face Transformers: load_custom_generate writes remote code to disk before the trust checkCVE-2026-80047 · Hugging Face Transformers (dynamic_module_utils.py, load_custom_generate remote-code cache)Unscored
- SGLang: unauthenticated pickle deserialization on /update_weights_from_tensor gives code executionCVE-2026-86793 · SGLang inference server (/update_weights_from_tensor, SafeUnpickler)Unscored
- Jupyter Notebook (untrusted notebooks): Untrusted notebook executes JavaScript in the user's session on openCVE-2021-32798 · Jupyter Notebook (untrusted notebooks)Critical
- MLflow: Absolute path traversal prior to 2.5.0CVE-2023-3765 · MLflowCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.