Cross-Site Scripting Vulnerability in SillyTavern User Interface
CVE-2026-44651
6.9MEDIUM
What is CVE-2026-44651?
SillyTavern, a user interface for interacting with various AI models, is susceptible to a cross-site scripting (XSS) vulnerability. Versions prior to 1.18.0 do not adequately escape attacker-controlled URL values when handling errors during proxy operations, allowing potentially malicious scripts to be injected and executed in the user's browser. This issue poses risks to user data and confidentiality, necessitating an upgrade to version 1.18.0 or later for protection.
Affected Version(s)
SillyTavern < 1.18.0
