CVE Explorer
CVE-2026-58198
ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by tar.extractall(path=self.data_path), allowing a local attacker who pre-plants a symlink at the predictable path to cause archive contents to be written through the symlink to an attacker-chosen directory. This issue is fixed in version 1.2.14
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-367","description":"CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"ChatterBot","vendor":"gunthercox","versions":[{"status":"affected","version":"< 1.2.14"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-367","description":"CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/gunthercox/ChatterBot/commit/82817b5c28bfd43e682b991bcc76e6f780726dbf","tags":["x_refsource_MISC"],"url":"https://github.com/gunthercox/ChatterBot/commit/82817b5c28bfd43e682b991bcc76e6f780726dbf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/references/2
{"name":"https://github.com/gunthercox/ChatterBot/pull/2445","tags":["x_refsource_MISC"],"url":"https://github.com/gunthercox/ChatterBot/pull/2445"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/references/1
{"name":"https://github.com/gunthercox/ChatterBot/releases/tag/1.2.14","tags":["x_refsource_MISC"],"url":"https://github.com/gunthercox/ChatterBot/releases/tag/1.2.14"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/references/3
{"name":"https://github.com/gunthercox/ChatterBot/security/advisories/GHSA-wvrh-2f4m-924v","tags":["x_refsource_CONFIRM"],"url":"https://github.com/gunthercox/ChatterBot/security/advisories/GHSA-wvrh-2f4m-924v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/cna/references/0
{"tags":["exploit"],"url":"https://github.com/gunthercox/ChatterBot/security/advisories/GHSA-wvrh-2f4m-924v"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9a1866c4d5b4fe0429e7ba16e0f8bb7b0cfedfbf13f63950e72b115dfe9eefa4 · sha256:0100fb5a094301b0… · /containers/adp/0/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.