What happened
NVD published a coordinated batch (CVE-2026-51882, CVE-2026-51883, CVE-2026-51884) of path-traversal issues in Langchain-Chatchat covering the file-upload, knowledge-base-creation, and temp-document-upload paths, allowing writes outside the configured storage boundaries.
Why it matters
Langchain-Chatchat is a widely used self-hosted RAG chatbot stack; file-write primitives on it can be chained to overwrite server files or stage payloads in the RAG/ingestion pipeline that feeds the LLM context.
Attack vector
Crafted filenames or knowledge_base_name values containing traversal sequences write files to arbitrary locations outside the intended openai_files / knowledge-base / temp-doc directories on the server.
Affected systems
Langchain-Chatchat 0.3.0 and 0.3.1 (OpenAI-compatible /v1/files endpoint, knowledge-base creation, /knowledge_base/upload_temp_docs)
Mitigation
Apply upstream fixes once available (GitHub issues chatchat-space/Langchain-Chatchat#5468 / #5467 areas); restrict upload endpoints to authenticated/trusted users.