{"id":"CVE-2026-28795","aliases":["GHSA-vmwq-8g8c-jm79","PYSEC-2026-2794"],"url":"https://o3.security/vulnerability/CVE-2026-28795","summary":"OpenChatBI: Critical Path Traversal Vulnerability in save_report Tool of OpenChatBI","details":"### Impact\nThe `save_report` tool in `openchatbi/tool/save_report.py` suffers from a critical path traversal vulnerability due to insufficient input sanitization of the `file_format` parameter. \n\nThe function only removes leading dots of `file_format` using `file_format.lstrip(\".\")` but allows path traversal sequences like `/../../` to pass through unchanged. When the filename is constructed via string concatenation in \n\n    f\"{timestamp}_{clean_title}.{file_format}\"\n\nmalicious path sequences are preserved, enabling attackers to write files outside the designated report directory. \n\nAn attacker can manipulate the LLM to call the tool with a specific `file_format` to overwrite critical system files like `__init__.py`, potentially leading to remote code execution.\n\n\n### Patches\n- Affected versions:\n<=0.2.1\n- Patched versions:\n0.2.2 (includes fix from PR #12: https://github.com/zhongyu09/openchatbi/pull/12)\n\n### Workarounds\nNo\n\n### References\n- Issue #10: https://github.com/zhongyu09/openchatbi/issues/10\n- PR #12: https://github.com/zhongyu09/openchatbi/pull/12","published":"2026-03-06T06:21:52.789Z","modified":"2026-08-12T03:51:31.718965376Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"openchatbi","fixedVersion":"0.2.2"}],"fix":{"url":"https://github.com/zhongyu09/openchatbi/commit/372a7e861da5159c3106d64d6f6edf8284db8c75","label":"zhongyu09/openchatbi@372a7e8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28795.json"},{"type":"ADVISORY","url":"https://github.com/zhongyu09/openchatbi/security/advisories/GHSA-vmwq-8g8c-jm79"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28795"},{"type":"REPORT","url":"https://github.com/zhongyu09/openchatbi/issues/10"},{"type":"FIX","url":"https://github.com/zhongyu09/openchatbi/commit/372a7e861da5159c3106d64d6f6edf8284db8c75"},{"type":"FIX","url":"https://github.com/zhongyu09/openchatbi/pull/12"},{"type":"PACKAGE","url":"https://github.com/zhongyu09/openchatbi"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.718965376Z"}}