sillytavern
11 known vulnerabilities · 0 critical · 2 high
SillyTavern has a SSRF vulnerability in the CORS proxy middleware
SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
SillyTavern: Path Traversal allows file existence oracle
SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
SillyTavern has a Path Traversal issue
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
SillyTavern has Authentication Bypass via SSO Header Injection