CVE-2026-34523 is a path traversal vulnerability in SillyTavern versions prior to 1.17.0, allowing unauthenticated attackers to determine the existence of files on the server's filesystem by sending specially crafted requests. Rated as Medium severity (CVSS 5.3), this vulnerability has a network attack vector and low attack complexity, with a potential impact limited to information disclosure regarding file presence. There is currently no evidence of active exploitation, nor is public exploit code available, and community discussion or media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.0CPE matchmatch criteria | cpe:2.3:a:sillytavern:sillytavern:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.