A vulnerability, which was classified as critical, has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This issue affects some unknown processing of the file /v1/file. The manipulation of the argument flag leads to path traversal. The exploit has been disclosed to the public and may be used.
{
"cwe_ids": [
"CWE-22"
],
"cna_assigner": "VulDB",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/6xxx/CVE-2025-6855.json"
}{
"cpe": "cpe:2.3:a:chatchat-space:langchain-chatchat:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0.3.0"
},
{
"last_affected": "0.3.0"
},
{
"introduced": "0.3.1"
},
{
"last_affected": "0.3.1"
},
{
"introduced": "0"
}
],
"source": [
"AFFECTED_FIELD",
"CPE_RANGE"
]
}