Executive brief
SillyTavern, a user interface for interacting with text generation AI, contains a security flaw in its proxy service. An attacker can use this vulnerability to run malicious scripts in a user's browser if they are tricked into clicking a specifically crafted link. This could lead to the theft of login tokens or unauthorized manipulation of the user's session.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in SillyTavern's CORS proxy middleware within `src/middleware/corsProxy.js`. The root cause is the improper neutralization of the `url` parameter in the `GET /proxy/:url(*)` route; when a fetch request fails, the application reflects the raw, unescaped URL back into a 500 error response body. An attacker can exploit this by crafting a URL containing malicious HTML/JavaScript tags. If a victim visits the crafted link, the script executes in their browser context. The issue is fixed in version 1.18.0 by ensuring user-provided URLs are no longer reflected in the response body.
Affected products
- SillyTavern SillyTavern <= 1.17.0
Timeline
- 2026-05-11: disclosed
- 2026-05-12: advisory: GitHub Advisory published
- 2026-05-29: other: NVD published