Vulnerabilities/

SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user

Severity:
High

Description

A Path Traversal vulnerability in chat endpoints allows an authenticated attacker to read and delete arbitrary files under their user data root (for example secrets.json and settings.json) by supplying avatar_url="..".

Recommendation

Update the sillytavern package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
sillytavern
Anything's wrong? Let us know Last updated on April 06, 2026