CVE-2025-6853 | chatchat-space Langchain-Chatchat up to 0.3.1 Backend upload_temp_docs flag path traversal (Issue 5352 / EUVD-2025-19477)
A vulnerability labeled as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. Affected is the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend. Such manipulation of the argument flag leads to path traversal.
This vulnerability is traded as CVE-2025-6853. The attack may be launched remotely. Furthermore, there is an exploit available.