PT-2026-42041 · Sillytavern+1 · Sillytavern
Larlarua
·
Published
2026-05-19
·
Updated
2026-05-29
·
CVE-2026-46372
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
SillyTavern versions prior to 1.18.0
Description
SillyTavern is a locally installed user interface for interacting with large language models, image generation engines, and text-to-speech models. The application contains a Server-Side Request Forgery (SSRF) issue—a flaw where a server is tricked into making requests to an unintended location—via the '/api/search/searxng' endpoint. An authenticated low-privilege user can provide a malicious
baseUrl variable, which the server uses to build outbound fetches without performing allowlist, IP range, DNS, or scheme validation. This allows an attacker to point the request toward internal or loopback HTTP services and receive the response body, potentially disclosing information from internal admin panels, development services, or cloud metadata endpoints.Recommendations
Update to version 1.18.0.
Enable and properly configure the Private Request Whitelisting filter, especially when the instance is hosted over a network.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sillytavern