CVE-2026-28795 | zhongyu09 openchatbi up to 0.2.1 save_report.py file_format path traversal
A vulnerability categorized as critical has been discovered in zhongyu09 openchatbi up to 0.2.1. This issue affects some unknown processing of the file openchatbi/tool/save_report.py. Such manipulation of the argument file_format leads to path traversal.
This vulnerability is traded as CVE-2026-28795. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.