Junglewise Threat Intelligence

CVE-2026-34524: SillyTavern path traversal in chat endpoints

CVE-2026-34524 · Severity: high · CVSS 8.3 · Published 2026-04-02

Technologies: Sillytavern. Vendors: npm.

Executive brief

SillyTavern is a user interface for interacting with AI models and image generation engines. A security flaw allows logged-in users to access or delete sensitive files on the server that they should not be able to reach, such as configuration settings and secret keys. This could lead to the theft of API credentials or the disruption of the service for other users.

Technical details

A path traversal vulnerability exists in the `/api/chats/export` and `/api/chats/delete` endpoints of SillyTavern. The root cause is an insufficient input validator in `src/middleware/validateFileName.js` that fails to block directory traversal sequences (e.g., '..') in the `avatar_url` parameter. By supplying a crafted `avatar_url` value, an authenticated attacker can escape the intended 'chats' directory to access the user data root. This allows for the unauthorized reading or deletion of sensitive files like `secrets.json` and `settings.json`. The issue is resolved in version 1.17.0 by improving path validation.

Affected products

  • SillyTavern SillyTavern < 1.17.0

Timeline

  • 2026-03-28: patched: Version 1.17.0 released
  • 2026-03-30: advisory: GitHub Security Advisory published
  • 2026-04-02: disclosed: CVE published to NVD

References

Related threats