<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 23:38:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-280149</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280149</link>
      <description>EUVD-2026-280149</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280149</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34523</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34523</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in the static file route handler allows any unauthenticated user to determine whether files exist anywhere on the server&amp;#39;s filesystem. by sending percent-encoded &amp;#34;../&amp;#34; sequences (%2E%2E%2F) in requests to static file routes, an attacker can check for the existence of files. This issue has been patched in version 1.17.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability in the static file route handler allows any unauthenticated user to determine whether files exist anywhere on the server&amp;#39;s filesystem. by sending percent-encoded &amp;#34;../&amp;#34; sequences (%2E%2E%2F) in requests to static file routes, an attacker can check for the existence of files. This issue has been patched in version 1.17.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34523</guid>
    </item>
    <item>
      <title>GHSA-525j-2hrj-m8fp — SillyTavern: Path Traversal allows file existence oracle</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-525j-2hrj-m8fp</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A path traversal vulnerability in the static file route handler allows any unauthenticated user to determine whether files exist anywhere on the server&amp;#39;s filesystem. By sending percent-encoded `../` sequences (`%2E%2E%2F`) in requests to static file routes, an attacker can check for the existence of files (404 if it doesn&amp;#39;t exist, 403 means it exists).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in `createRouteHandler` (`src/users.js:947–963`), which backs all user-data static file routes:&lt;/p&gt;
&lt;p&gt;```javascript
function createRouteHandler(directoryFn) {
    return async (req, res) =&amp;gt; {
        const directory = directoryFn(req);
        const filePath = decodeURIComponent(req.params[0]);
        const exists = fs.existsSync(path.join(directory, filePath)); // no boundary check here
        if (!exists) {
            return res.sendStatus(404);
        }
        return res.sendFile(filePath, { root: directory });
    };
}
```&lt;/p&gt;
&lt;p&gt;`req.params[0]` contains the raw (percent-encoded) wildcard from the URL. After `decodeURIComponent`, a request path like `/characters/%2E%2E%2F%2E%2E%2FUsers/kirakira` decodes to `../../Users/kirakira`, and `path.join` resolves it outside the intended directory. `res.sendFile` correctly blocks the file from being served (the `send` module&amp;#39;s root check returns 403), but `fs.existsSync` had already run, and the 403/404 distinction reveals the result.&lt;/p&gt;
&lt;p&gt;Affected routes (they all use the same handler, so they&amp;#39;re all affected):&lt;/p&gt;
&lt;p&gt;- `/characters/*`
- `/user/files…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;A path traversal vulnerability in the static file route handler allows any unauthenticated user to determine whether files exist anywhere on the server&amp;#39;s filesystem. By sending percent-encoded `../` sequences (`%2E%2E%2F`) in requests to static file routes, an attacker can check for the existence of files (404 if it doesn&amp;#39;t exist, 403 means it exists).&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerability is in `createRouteHandler` (`src/users.js:947–963`), which backs all user-data static file routes:&lt;/p&gt;
&lt;p&gt;```javascript
function createRouteHandler(directoryFn) {
    return async (req, res) =&amp;gt; {
        const directory = directoryFn(req);
        const filePath = decodeURIComponent(req.params[0]);
        const exists = fs.existsSync(path.join(directory, filePath)); // no boundary check here
        if (!exists) {
            return res.sendStatus(404);
        }
        return res.sendFile(filePath, { root: directory });
    };
}
```&lt;/p&gt;
&lt;p&gt;`req.params[0]` contains the raw (percent-encoded) wildcard from the URL. After `decodeURIComponent`, a request path like `/characters/%2E%2E%2F%2E%2E%2FUsers/kirakira` decodes to `../../Users/kirakira`, and `path.join` resolves it outside the intended directory. `res.sendFile` correctly blocks the file from being served (the `send` module&amp;#39;s root check returns 403), but `fs.existsSync` had already run, and the 403/404 distinction reveals the result.&lt;/p&gt;
&lt;p&gt;Affected routes (they all use the same handler, so they&amp;#39;re all affected):&lt;/p&gt;
&lt;p&gt;- `/characters/*`
- `/user/files…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-525j-2hrj-m8fp</guid>
    </item>
  </channel>
</rss>
