Cross-Site Scripting Vulnerability in SillyTavern User Interface
CVE-2026-44651

6.9MEDIUM

Key Information:

Vendor
CVE Published:
29 May 2026

What is CVE-2026-44651?

SillyTavern, a user interface for interacting with various AI models, is susceptible to a cross-site scripting (XSS) vulnerability. Versions prior to 1.18.0 do not adequately escape attacker-controlled URL values when handling errors during proxy operations, allowing potentially malicious scripts to be injected and executed in the user's browser. This issue poses risks to user data and confidentiality, necessitating an upgrade to version 1.18.0 or later for protection.

Affected Version(s)

SillyTavern < 1.18.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.