<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 19:15:04 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-322958</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-322958</link>
      <description>EUVD-2026-322958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-322958</guid>
    </item>
    <item>
      <title>fkie_cve-2026-44650</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44650</link>
      <description>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: &amp;#34;.&amp;#34; which bypasses sanitize-filename validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in the default configuration. This vulnerability is fixed in 1.18.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint accepts extensionName: &amp;#34;.&amp;#34; which bypasses sanitize-filename validation, causing the entire user extensions directory to be recursively deleted. No authentication is required in the default configuration. This vulnerability is fixed in 1.18.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-44650</guid>
    </item>
    <item>
      <title>GHSA-886q-f44j-h6wh — SillyTavern has a Path Traversal issue</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-886q-f44j-h6wh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`POST /api/extensions/delete` endpoint accepts `extensionName: &amp;#34;.&amp;#34;` which bypasses 
`sanitize-filename` validation, causing the entire user extensions directory to be 
recursively deleted. No authentication is required in the default configuration.&lt;/p&gt;
&lt;p&gt;## Affected File&lt;/p&gt;
&lt;p&gt;`src/endpoints/extensions.js` (last modified: commit `3ad9b05e2`)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The validation check occurs **before** sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
// [1] &amp;#34;.&amp;#34; is truthy — passes the check
if (!request.body.extensionName) {
    return response.status(400).send(&amp;#39;Bad Request&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;// [2] sanitize(&amp;#34;.&amp;#34;)  →  &amp;#34;&amp;#34;
const extensionPath = path.join(basePath, sanitize(extensionName));
// path.join(&amp;#34;data\\default-user\\extensions&amp;#34;, &amp;#34;&amp;#34;)
// = &amp;#34;data\\default-user\\extensions&amp;#34;  ← basePath itself!&lt;/p&gt;
&lt;p&gt;// [3] Deletes the entire extensions directory
await fs.promises.rm(extensionPath, { recursive: true });
```&lt;/p&gt;
&lt;p&gt;`sanitize-filename` converts `&amp;#34;.&amp;#34;` to `&amp;#34;&amp;#34;` (documented behavior).  
`path.join(basePath, &amp;#34;&amp;#34;)` returns `basePath` itself.  
Result: the entire `data\default-user\extensions\` directory is deleted.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on: Windows 10, SillyTavern v1.17.0, commit `004f1336e`  
Authentication: none (basicAuthMode: false, default configuration)&lt;/p&gt;
&lt;p&gt;Run in browser console (F12) while SillyTavern is open:&lt;/p&gt;
&lt;p&gt;```javascript
async function poc() {
    const { token } = await (await fetch(&amp;#39;/csrf-token&amp;#39;)).json();
    const headers = {
        &amp;#39;Content-Type&amp;#39;: &amp;#39;application/json&amp;#39;,
        &amp;#39;X-CSRF-Token&amp;#39;: token,
    };&lt;/p&gt;
&lt;p&gt;//…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sillytavern&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`POST /api/extensions/delete` endpoint accepts `extensionName: &amp;#34;.&amp;#34;` which bypasses 
`sanitize-filename` validation, causing the entire user extensions directory to be 
recursively deleted. No authentication is required in the default configuration.&lt;/p&gt;
&lt;p&gt;## Affected File&lt;/p&gt;
&lt;p&gt;`src/endpoints/extensions.js` (last modified: commit `3ad9b05e2`)&lt;/p&gt;
&lt;p&gt;## Root Cause&lt;/p&gt;
&lt;p&gt;The validation check occurs **before** sanitization:&lt;/p&gt;
&lt;p&gt;```javascript
// [1] &amp;#34;.&amp;#34; is truthy — passes the check
if (!request.body.extensionName) {
    return response.status(400).send(&amp;#39;Bad Request&amp;#39;);
}&lt;/p&gt;
&lt;p&gt;// [2] sanitize(&amp;#34;.&amp;#34;)  →  &amp;#34;&amp;#34;
const extensionPath = path.join(basePath, sanitize(extensionName));
// path.join(&amp;#34;data\\default-user\\extensions&amp;#34;, &amp;#34;&amp;#34;)
// = &amp;#34;data\\default-user\\extensions&amp;#34;  ← basePath itself!&lt;/p&gt;
&lt;p&gt;// [3] Deletes the entire extensions directory
await fs.promises.rm(extensionPath, { recursive: true });
```&lt;/p&gt;
&lt;p&gt;`sanitize-filename` converts `&amp;#34;.&amp;#34;` to `&amp;#34;&amp;#34;` (documented behavior).  
`path.join(basePath, &amp;#34;&amp;#34;)` returns `basePath` itself.  
Result: the entire `data\default-user\extensions\` directory is deleted.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;Tested on: Windows 10, SillyTavern v1.17.0, commit `004f1336e`  
Authentication: none (basicAuthMode: false, default configuration)&lt;/p&gt;
&lt;p&gt;Run in browser console (F12) while SillyTavern is open:&lt;/p&gt;
&lt;p&gt;```javascript
async function poc() {
    const { token } = await (await fetch(&amp;#39;/csrf-token&amp;#39;)).json();
    const headers = {
        &amp;#39;Content-Type&amp;#39;: &amp;#39;application/json&amp;#39;,
        &amp;#39;X-CSRF-Token&amp;#39;: token,
    };&lt;/p&gt;
&lt;p&gt;//…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-886q-f44j-h6wh</guid>
    </item>
  </channel>
</rss>
