Server-Side Fetch Vulnerability in SillyTavern by SillyTavern
CVE-2026-46372

8.5HIGH

Key Information:

Vendor
CVE Published:
29 May 2026

What is CVE-2026-46372?

SillyTavern, an interface for interacting with AI models, has a vulnerability where an authenticated low-privilege user can manipulate the API endpoint '/api/search/searxng'. This exploit involves supplying a controlled baseUrl that the application uses to make outbound HTTP requests. By redirecting the requests to internal or loopback services, attackers can potentially leak sensitive data. This issue is addressed in version 1.18.0, reinforcing the importance of maintaining updated software versions.

Affected Version(s)

SillyTavern < 1.18.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.