Path Traversal Vulnerability in SillyTavern User Interface
CVE-2026-34524
8.3HIGH
What is CVE-2026-34524?
SillyTavern, a locally installed user interface designed for interacting with text generation models, has a path traversal vulnerability that could be exploited by an authenticated attacker. By manipulating the 'avatar_url' parameter, an attacker can access and potentially delete sensitive files located in the user's data root, such as secrets.json and settings.json. This vulnerability has been addressed in version 1.17.0, enhancing user data protection.
Affected Version(s)
SillyTavern < 1.17.0
