Executive brief
libre-chat is a Python-based chat application that allows users to upload document files. A path traversal vulnerability in the file upload handler permits attackers to write files to arbitrary locations on the server by supplying crafted filenames (e.g., ../../../test.txt), potentially compromising the application or the underlying system.
Technical details
The vulnerability is a classic path traversal (CWE-22) flaw in the upload_documents method of libre-chat v0.0.6. The upload handler fails to properly sanitize or validate filenames provided by users in multipart file uploads, allowing an attacker to use directory traversal sequences (../) to escape the intended upload directory and write files to arbitrary locations. The attack requires network access to the upload endpoint and no authentication is specified as required. A successful exploit enables arbitrary file write, which could lead to remote code execution, configuration tampering, or denial of service. A patch was available via GitHub pull request #9 and commit dbb8e340.
Affected products
- libre-chat libre-chat 0.0.4 through 0.0.6
Timeline
- 2024-07-31: disclosed: Vulnerability reported via GitHub issue #10
- 2024-11-25: patched: Fix merged via PR #9 and commit dbb8e340
- 2024-11-25: advisory: GHSA and CVE published