Junglewise Threat Intelligence

CVE-2026-44652: SillyTavern SSRF in CORS proxy middleware

CVE-2026-44652 · Severity: medium · CVSS 4 · Published 2026-05-29

Technologies: Sillytavern. Vendors: npm.

Executive brief

SillyTavern, a popular interface for large language models, contains a security flaw in its optional CORS proxy feature. This vulnerability allows an attacker to force the server to make unauthorized requests to internal network resources or sensitive metadata endpoints. If exploited, this could lead to the exposure of private internal data or allow an attacker to probe the local network where the application is hosted.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in SillyTavern's `corsProxyMiddleware` located at `src/middleware/corsProxy.js`. The component fails to validate the `url` parameter before passing it to the `fetch()` function, only blocking circular requests to its own host. An unauthenticated remote attacker can exploit this by sending crafted requests to the `/proxy/` endpoint to reach internal network services, loopback addresses, or cloud metadata services. This can result in the exfiltration of sensitive responses from internal infrastructure. The issue is addressed in version 1.18.0 by the introduction of a configurable private request whitelisting filter.

Affected products

  • SillyTavern SillyTavern <= 1.17.0

Timeline

  • 2026-05-11: disclosed
  • 2026-05-12: advisory: GitHub Advisory GHSA-ccfq-2454-f5xw published
  • 2026-05-11: patched: Version 1.18.0 released

References

Related threats