OpenBMB ChatDev through version 2.2.0 is affected by CVE-2026-58166, a critical unauthenticated path traversal flaw in its file upload handler that lets remote attackers write or delete arbitrary files on the server. The vulnerability stems from the POST uploads session endpoint, where a malicious multipart filename containing traversal sequences or an absolute path is passed into save_upload_file without proper sanitization, allowing attacker-controlled filesystem paths to be used during upload and cleanup operations.
The issue is rated CVSS 3.1 9.1 (Critical), with a listed CVSS 4.0 8.8 (High), and is considered remotely exploitable without authentication. The flaw was fixed in commit 4fd4da6, and affected organizations should update to a patched release and enforce strict validation and sanitization of upload filenames and paths to prevent arbitrary file write or deletion.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
A path traversal vulnerability in OpenBMB ChatDev's upload handler, affecting versions through 2.2.0, was fixed in commit 4fd4da6. The flaw allowed unauthenticated remote attackers to write or delete arbitrary files via a malicious multipart filename sent to the upload endpoint.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.