OpenChatBI is an intelligent chat-based BI tool powered by large language models, designed to help users query, analyze, and visualize data through natural language conversations. Prior to version 0.2.2, the save_report tool in openchatbi/tool/save_report.py suffers from a critical path traversal vulnerability due to insufficient input sanitization of the file_format parameter. This issue has been patched in version 0.2.2.
References
| Link | Resource |
|---|---|
| https://github.com/zhongyu09/openchatbi/commit/372a7e861da5159c3106d64d6f6edf8284db8c75 | Patch |
| https://github.com/zhongyu09/openchatbi/issues/10 | Issue Tracking |
| https://github.com/zhongyu09/openchatbi/pull/12 | Issue Tracking Patch |
| https://github.com/zhongyu09/openchatbi/security/advisories/GHSA-vmwq-8g8c-jm79 | Patch Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-06 07:16
Updated : 2026-06-17 10:29
NVD link : CVE-2026-28795
Mitre link : CVE-2026-28795
CVE.ORG link : CVE-2026-28795
JSON object : View
Products Affected
zhongyu09
- openchatbi
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
