VDB
Sign up
—

PYSEC-2026-2794

OpenChatBI has a Path Traversal Vulnerability in save_report Tool

Quick fix

PYSEC-2026-2794 — openchatbi: upgrade to the fixed version with the command below.

pip install --upgrade 'openchatbi>=0.2.2'

Details

### Impact The `save_report` tool in `openchatbi/tool/save_report.py` suffers from a critical path traversal vulnerability due to insufficient input sanitization of the `file_format` parameter.

The function only removes leading dots of `file_format` using `file_format.lstrip(".")` but allows path traversal sequences like `/../../` to pass through unchanged. When the filename is constructed via string concatenation in

f"{timestamp}_{clean_title}.{file_format}"

malicious path sequences are preserved, enabling attackers to write files outside the designated report directory.

An attacker can manipulate the LLM to call the tool with a specific `file_format` to overwrite critical system files like `__init__.py`, potentially leading to remote code execution.

### Patches - Affected versions: <=0.2.1 - Patched versions: 0.2.2 (includes fix from PR #12: https://github.com/zhongyu09/openchatbi/pull/12)

### Workarounds No

### References - Issue #10: https://github.com/zhongyu09/openchatbi/issues/10 - PR #12: https://github.com/zhongyu09/openchatbi/pull/12

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/openchatbi
Introduced in: 0Fixed in: 0.2.2
Fixpip install --upgrade 'openchatbi>=0.2.2'

References