<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 13:39:27 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280044</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280044</link>
      <description>EUVD-2026-280044</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280044</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34522</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34522</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name. This issue has been patched in version 1.17.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name. This issue has been patched in version 1.17.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34522</guid>
    </item>
    <item>
      <title>GHSA-xvww-xhx6-22pf — SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xvww-xhx6-22pf</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability in `/api/chats/import` allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into `character_name`.&lt;/p&gt;
&lt;p&gt;### Details
`character_name` is used unsafely as part of the destination filename and then passed into `path.join(...)` without sanitization.&lt;/p&gt;
&lt;p&gt;Evidence:
- Import handler entrypoint:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L680-L686&amp;gt;
- Unsanitized `character_name` used in output filename:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L719-L723&amp;gt;
- Same write pattern in JSONL import branch:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L759-L766&amp;gt;
- Endpoint auth context (authenticated user access):  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/server-main.js#L239&amp;gt;&lt;/p&gt;
&lt;p&gt;Example payload:
- `character_name=../../../../tmp/st_poc`&lt;/p&gt;
&lt;p&gt;This causes the final destination path to escape from `&amp;lt;user&amp;gt;/chats/&amp;lt;avatar&amp;gt;/...` and write to an attacker-controlled location such as `/tmp/...` (or any writable path for the service account).&lt;/p&gt;
&lt;p&gt;### PoC
Prerequisites:
- Valid authenticated session cookie (`cookie.txt`)
- Valid CSRF token (`$TOKEN`)&lt;/p&gt;
&lt;p&gt;Prepare payload:&lt;/p&gt;
&lt;p&gt;```bash
printf &amp;#39;{&amp;#34;user_name&amp;#34;:&amp;#34;u&amp;#34;,&amp;#34;chat_metadata&amp;#34;:{}}…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Summary
A path traversal vulnerability in `/api/chats/import` allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into `character_name`.&lt;/p&gt;
&lt;p&gt;### Details
`character_name` is used unsafely as part of the destination filename and then passed into `path.join(...)` without sanitization.&lt;/p&gt;
&lt;p&gt;Evidence:
- Import handler entrypoint:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L680-L686&amp;gt;
- Unsanitized `character_name` used in output filename:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L719-L723&amp;gt;
- Same write pattern in JSONL import branch:  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L759-L766&amp;gt;
- Endpoint auth context (authenticated user access):  
  &amp;lt;https://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/server-main.js#L239&amp;gt;&lt;/p&gt;
&lt;p&gt;Example payload:
- `character_name=../../../../tmp/st_poc`&lt;/p&gt;
&lt;p&gt;This causes the final destination path to escape from `&amp;lt;user&amp;gt;/chats/&amp;lt;avatar&amp;gt;/...` and write to an attacker-controlled location such as `/tmp/...` (or any writable path for the service account).&lt;/p&gt;
&lt;p&gt;### PoC
Prerequisites:
- Valid authenticated session cookie (`cookie.txt`)
- Valid CSRF token (`$TOKEN`)&lt;/p&gt;
&lt;p&gt;Prepare payload:&lt;/p&gt;
&lt;p&gt;```bash
printf &amp;#39;{&amp;#34;user_name&amp;#34;:&amp;#34;u&amp;#34;,&amp;#34;chat_metadata&amp;#34;:{}}…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xvww-xhx6-22pf</guid>
    </item>
  </channel>
</rss>
