Path Traversal Vulnerability in SillyTavern User Interface
CVE-2026-34524

8.3HIGH

Key Information:

Vendor
CVE Published:
2 April 2026

What is CVE-2026-34524?

SillyTavern, a locally installed user interface designed for interacting with text generation models, has a path traversal vulnerability that could be exploited by an authenticated attacker. By manipulating the 'avatar_url' parameter, an attacker can access and potentially delete sensitive files located in the user's data root, such as secrets.json and settings.json. This vulnerability has been addressed in version 1.17.0, enhancing user data protection.

Affected Version(s)

SillyTavern < 1.17.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.