CVE-2026-34524: SillyTavern: Path traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
Summary A Path Traversal vulnerability in chat endpoints allows an authenticated attacker to read and delete arbitrary files under their user data root (for example secrets.json and settings.json) by supplying avatarurl="..".
Details The input validator used by avatarurl blocks only / and NUL bytes, but does not block traversal segments like ...
Evidence: - Weak validator regex (does not reject ..): <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/middleware/validateFileName.js#L24-L27> - Vulnerable delete path construction: <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L575-L577> - Vulnerable export path construction: <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L595-L598> - Endpoint auth context (authenticated user access): <https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/server-main.js#L239>
Because avatarurl=".." is accepted, path.join(<user>/chats, "..") resolves to <user>/, enabling direct access to files outside the chats directory.
PoC Prerequisites: - Valid authenticated session cookie (cookie.txt) - Valid CSRF token ($TOKEN)
Read sensitive file (secrets.json):
bash curl -b cookie.txt -H "x-csrf-token: $TOKEN" -H "content-type: application/json" \ -d '{"avatarurl":"..","isgroup":false,"file":"secrets.json","format":"jsonl","exportfilename":"x"}' \ http://TARGET:8000/api/chats/export
Delete sensitive file (settings.json):
bash curl -b cookie.txt -H "x-csrf-token: $TOKEN" -H "content-type: application/json" \ -d '{"avatarurl":"..","chatfile":"settings.json"}' \ http://TARGET:8000/api/chats/delete
Impact - Confidentiality: exposed per-user secrets and config data. - Integrity/Availability: attacker can delete critical per-user files and break account operation. - Risk is significant in multi-user or remotely reachable deployments.
Resolution
The issue was addressed in version 1.17.0
Other sources
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in chat endpoints allows an authenticated attacker to read and delete arbitrary files under their user data root (for example secrets.json and settings.json) by supplying avatarurl="..". This issue has been patched in version 1.17.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/sillytavernto a version that resolves this vulnerability.Fixed in 1.17.0 - Upgrade
Upgrade
SillyTavernto a version that resolves this vulnerability.Fixed in 1.17.0 - Configuration
Update the avatar_url validator used by /api/chats/delete and /api/chats/export so it rejects traversal segments like ".." (the material notes prior validation blocked only "/" and NUL bytes).
SillyTavern chat endpoints (avatar_url validator) avatar_url path traversal validation = Reject traversal segments (e.g., block ".." components; currently only blocks "/" and NUL bytes)