CVE-2026-6855
published 2026-04-22CVE-2026-6855: A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir`…
PriorityP338high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.16%
5.8th percentile
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux_ai | — | — |
| rhelai3 | bootc-aws-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-cuda-rhel9 | — | — |
| rhelai3 | bootc-azure-rocm-rhel9 | — | — |
| rhelai3 | bootc-cuda-rhel9 | — | — |
| rhelai3 | bootc-gcp-cuda-rhel9 | — | — |
| rhelai3 | bootc-rocm-rhel9 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
InstructLab vulnerable to Path Traversal
ghsa·2026-04-22
CVE-2026-6855 [HIGH] CWE-22 InstructLab vulnerable to Path Traversal
InstructLab vulnerable to Path Traversal
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
GHSA
GHSA-pqmg-c2j8-fq92: A flaw was found in InstructLab
ghsa_unreviewed·2026-04-22
CVE-2026-6855 [HIGH] CWE-22 GHSA-pqmg-c2j8-fq92: A flaw was found in InstructLab
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
Red Hat
instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write
vendor_redhat·2026-04-15·CVSS 7.1
CVE-2026-6855 [HIGH] CWE-22 instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write
instructlab: InstructLab: Path traversal allows arbitrary directory creation and file write
A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in the chat session handler by manipulating the `logs_dir` parameter. This allows the attacker to create new directories and write files to arbitrary locations on the system, potentially leading to unauthorized data modification or disclosure.
Statement: This Moderate impact vulnerability in instructlab allows for path traversal due to an unsanitized `logs_dir` parameter within the chat session handler. An attacker could exploit this to create arbitrary directories and write files to arbitrary locations on the system. This affects Red Hat Enterprise Linux AI.
Mitigation: Mitigation for this issue is eit
No detection rules found.
No public exploits indexed.
2026-04-22
Published