CRITICAL9.1
PYSEC-2026-1537
libre-chat Path Traversal vulnerability
Details
An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/libre-chat
Introduced in:
0No fixed version published yet for libre-chat (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-52787[ADVISORY]
- https://github.com/vemonet/libre-chat/issues/10[WEB]
- https://github.com/vemonet/libre-chat/pull/9[WEB]
- https://github.com/vemonet/libre-chat/commit/dbb8e3400e5258112179783d74c9cc54310cb72b[WEB]
- https://gist.github.com/jxfzzzt/276a6e8cfbc54d2c2711bb51d8d3dff3[WEB]
- https://github.com/vemonet/libre-chat[PACKAGE]
- https://pypi.org/project/libre-chat[PACKAGE]
- https://github.com/advisories/GHSA-3864-rp2m-2qfj[ADVISORY]