Executive brief
SillyTavern is a user interface for interacting with AI models and image generation engines. A security vulnerability allows an authenticated user to force the server to make unauthorized requests to internal network services or local files. This could lead to the exposure of sensitive internal data, access to administrative panels, or the compromise of other services running on the same network that are not intended to be public.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `/api/search/searxng` route within `src/endpoints/search.js`. The endpoint accepts a user-provided `baseUrl` parameter and uses it to construct outbound HTTP requests using the `fetch()` API without performing validation against an allowlist, IP ranges, or schemes. An authenticated attacker with low privileges can provide a loopback (127.0.0.1) or internal network address as the `baseUrl`. The server will then fetch the content from the internal target and return the response body to the attacker. This can be used to bypass network firewalls and access internal metadata services, administrative interfaces, or other private network resources. The issue is addressed in version 1.18.0 by the introduction of a configurable private request whitelisting filter.
Affected products
- SillyTavern SillyTavern <= 1.17.0
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published
- 2026-05-29: disclosed: CVE published to NVD
- 2026-05-29: patched: Vulnerability fixed in version 1.18.0