highCVSS 7.1Vulnerability

CVE-2026-6855

A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.

Properties

summary
InstructLab vulnerable to Path Traversal
severity
high
epss_score
0.00164
cvss_score
7.1
ghsa_published
2026-04-22T15:31:40Z
source_url
https://github.com/advisories/GHSA-pqmg-c2j8-fq92
ghsa_updated
2026-04-29T22:02:44Z
ghsa_id
GHSA-pqmg-c2j8-fq92
cve_id
CVE-2026-6855
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
is_ghsa_only
false
epss_percentile
0.05842

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]pip/instructlab

AFFECTS (1)

[Software]pip/instructlab

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Explore deeper with Ninja Signal's threat intelligence graph