VDB
Sign up

package

npm/sillytavern

pkg:npm/sillytavern

HIGH8.3npm
GHSA-vprr-q85p-79mf· CVE-2026-34524

SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root

Modified: 4/6/2026

HIGH7.5npm
GHSA-wmm3-h9qj-p5v6· CVE-2026-44648

SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover

Modified: 6/9/2026