Junglewise Threat Intelligence

CVE-2024-52787: PYSEC-2026-1537 - libre-chat Path Traversal vulnerability

CVE-2024-52787 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: PyPI.

Executive brief

libre-chat is a Python-based chat application that allows users to upload document files. A path traversal vulnerability in the file upload handler permits attackers to write files to arbitrary locations on the server by supplying crafted filenames (e.g., ../../../test.txt), potentially compromising the application or the underlying system.

Technical details

The vulnerability is a classic path traversal (CWE-22) flaw in the upload_documents method of libre-chat v0.0.6. The upload handler fails to properly sanitize or validate filenames provided by users in multipart file uploads, allowing an attacker to use directory traversal sequences (../) to escape the intended upload directory and write files to arbitrary locations. The attack requires network access to the upload endpoint and no authentication is specified as required. A successful exploit enables arbitrary file write, which could lead to remote code execution, configuration tampering, or denial of service. A patch was available via GitHub pull request #9 and commit dbb8e340.

Affected products

  • libre-chat libre-chat 0.0.4 through 0.0.6

Timeline

  • 2024-07-31: disclosed: Vulnerability reported via GitHub issue #10
  • 2024-11-25: patched: Fix merged via PR #9 and commit dbb8e340
  • 2024-11-25: advisory: GHSA and CVE published

References