Server-Side Fetch Vulnerability in SillyTavern by SillyTavern
CVE-2026-46372
8.5HIGH
What is CVE-2026-46372?
SillyTavern, an interface for interacting with AI models, has a vulnerability where an authenticated low-privilege user can manipulate the API endpoint '/api/search/searxng'. This exploit involves supplying a controlled baseUrl that the application uses to make outbound HTTP requests. By redirecting the requests to internal or loopback services, attackers can potentially leak sensitive data. This issue is addressed in version 1.18.0, reinforcing the importance of maintaining updated software versions.
Affected Version(s)
SillyTavern < 1.18.0
