Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-19479 | A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. |
Github GHSA |
GHSA-8v8h-4pjx-rg73 | Langchain-Chatchat vulnerable to path traversal |
Fri, 31 Oct 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chatchat-space
Chatchat-space langchain-chatchat |
|
| CPEs | cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chatchat-space
Chatchat-space langchain-chatchat |
Mon, 30 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 29 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability classified as problematic was found in chatchat-space Langchain-Chatchat up to 0.3.1. This vulnerability affects unknown code of the file /v1/files?purpose=assistants. The manipulation leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Title | chatchat-space Langchain-Chatchat files path traversal | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-06-30T15:57:07.635Z
Reserved: 2025-06-28T10:37:58.388Z
Link: CVE-2025-6854
Updated: 2025-06-30T15:56:14.344Z
Status : Analyzed
Published: 2025-06-29T09:15:24.020
Modified: 2026-04-29T01:00:01.613
Link: CVE-2025-6854
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA