SillyTavern: Path Traversal allows file existence oracle
Modified: 4/6/2026
package
pkg:npm/sillytavern
SillyTavern: Path Traversal allows file existence oracle
Modified: 4/6/2026
SillyTavern Web Interface Vulnerable DNS Rebinding
Modified: 10/6/2025
SillyTavern has a Path Traversal issue
Modified: 5/12/2026
SillyTavern has a SSRF vulnerability in the CORS proxy middleware
Modified: 6/9/2026
SillyTavern has Authentication Bypass via SSO Header Injection
Modified: 6/9/2026
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
Modified: 6/9/2026
SillyTavern: Path Traversal in `/api/chats/export` and `/api/chats/delete` allows arbitrary file read/delete within user data root
Modified: 4/6/2026
SillyTavern: Incomplete IP validation in /api/search/visit allows SSRF via localhost and IPv6
Modified: 4/6/2026
SillyTavern: Existing sessions are not invalidated after password change, allowing session reuse and account takeover
Modified: 6/9/2026
SillyTavern has a reflected XSS vulnerability in the CORS proxy middleware
Modified: 6/9/2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
Modified: 4/6/2026