CVE-2026-58166Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename in the file upload endpoint. Attackers can send a crafted filename containing path traversal sequences or an absolute path to the POST uploads session endpoint, which constructs the destination path without sanitization in save_upload_file, causing file write and cleanup operations to target attacker-chosen paths on the server filesystem.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-30: 106-30
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Unauthenticated arbitrary file write/delete via upload path traversal (CVE-2026-58166) OpenBMB ChatDev through 2.2.0 is vulnerable to an unauthenticated path traversal in its file upload handling, specifically in the uploads session endpoint where save_upload_file builds the destination path. The root cause is improper input validation/path sanitization, allowing traversal sequences (../) or absolute paths in the multipart filename to be used directly in filesystem operations. An attacker can exploit this remotely with no privileges by submitting a crafted multipart upload that forces the server to write to or delete files outside the intended upload directory. Real-world impact includes overwriting or removing critical application/system files, leading to denial of service and potentially further compromise depending on what files can be targeted. 👉 Affected: OpenBMB ChatDev <= 2.2.0 | Upgrade to commit 4fd4da6 (or a release containing it)

    Post summary

    OpenBMB ChatDev versions <= 2.2.0 are vulnerable to unauthenticated arbitrary file write/delete via upload path traversal (CVE-2026-58166); users should upgrade to commit 4fd4da6 or a later release to remediate the flaw.

    00000105
    232 followersView on X

Explore more