CVE-2025-6855 | chatchat-space Langchain-Chatchat up to 0.3.1 /v1/file flag path traversal (Issue 5354 / EUVD-2025-19478)
A vulnerability described as critical has been identified in chatchat-space Langchain-Chatchat up to 0.3.1. Affected by this issue is some unknown functionality of the file /v1/file. Executing manipulation of the argument flag can lead to path traversal.
This vulnerability is handled as CVE-2025-6855. The attack can only be done within the local network. Additionally, an exploit exists.