CVE-2026-58198: Gunthercox Chatterbot

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by tar.extractall(path=self.data_path), allowing a local attacker who pre-plants a symlink at the predictable path to cause archive contents to be written through the symlink to an attacker-chosen directory. This issue is fixed in version 1.2.14.

Affected products

  • Gunthercox Chatterbot: before 1.2.14 (fixed in 1.2.14)

Published 2026-07-09. Last modified 2026-07-09.