<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T18:19:23.006118+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-322958</id>
    <title>EUVD-2026-322958</title>
    <updated>2026-10-07T18:19:23.074867+00:00</updated>
    <content>EUVD-2026-322958</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-322958"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44650</id>
    <title>fkie_cve-2026-44650</title>
    <updated>2026-10-07T18:19:23.074910+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: "." which bypasses sanitize-filename validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in the default configuration. This vulnerability is fixed in 1.18.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44650"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-886q-f44j-h6wh</id>
    <title>GHSA-886q-f44j-h6wh — SillyTavern has a Path Traversal issue</title>
    <updated>2026-10-07T18:19:23.074946+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sillytavern</p>
<p>## Summary</p>
<p>`POST /api/extensions/delete` endpoint accepts `extensionName: "."` which bypasses 
`sanitize-filename` validation, causing the entire user extensions directory to be 
recursively deleted. No authentication is required in the default configuration.</p>
<p>## Affected File</p>
<p>`src/endpoints/extensions.js` (last modified: commit `3ad9b05e2`)</p>
<p>## Root Cause</p>
<p>The validation check occurs **before** sanitization:</p>
<p>```javascript
// [1] "." is truthy — passes the check
if (!request.body.extensionName) {
    return response.status(400).send('Bad Request');
}</p>
<p>// [2] sanitize(".")  →  ""
const extensionPath = path.join(basePath, sanitize(extensionName));
// path.join("data\\default-user\\extensions", "")
// = "data\\default-user\\extensions"  ← basePath itself!</p>
<p>// [3] Deletes the entire extensions directory
await fs.promises.rm(extensionPath, { recursive: true });
```</p>
<p>`sanitize-filename` converts `"."` to `""` (documented behavior).  
`path.join(basePath, "")` returns `basePath` itself.  
Result: the entire `data\default-user\extensions\` directory is deleted.</p>
<p>## Proof of Concept</p>
<p>Tested on: Windows 10, SillyTavern v1.17.0, commit `004f1336e`  
Authentication: none (basicAuthMode: false, default configuration)</p>
<p>Run in browser console (F12) while SillyTavern is open:</p>
<p>```javascript
async function poc() {
    const { token } = await (await fetch('/csrf-token')).json();
    const headers = {
        'Content-Type': 'application/json',
        'X-CSRF-Token': token,
    };</p>
<p>//…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-886q-f44j-h6wh"/>
  </entry>
</feed>
