Executive brief
SillyTavern, an interface for interacting with text generation AI, contains a flaw in how it handles Single Sign-On (SSO) logins. An attacker can bypass security controls by sending specially crafted network requests that impersonate any user, including administrators. This could lead to a full account takeover, allowing unauthorized access to private data and administrative settings.
Technical details
SillyTavern implements header-based SSO for Authelia and Authentik using the 'Remote-User' and 'X-Authentik-Username' headers. The application fails to validate that these headers originate from a trusted reverse proxy, allowing any client with network access to the SillyTavern port to inject them. Furthermore, a user enumeration vulnerability in the '/api/users/list' endpoint allows unauthenticated attackers to discover valid usernames to target. By combining these, an attacker can obtain an authenticated session for any user, including administrators. The issue is fixed in version 1.18.0 by introducing an IP allowlist for SSO headers.
Affected products
- SillyTavern SillyTavern <= 1.17.0
Timeline
- 2026-05-11: disclosed
- 2026-05-11: patched: Fixed in version 1.18.0
- 2026-05-12: advisory