sillytavern
npm11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sillytavernpage 1 of 1
- CVE-2025-59159CRITICALCVSS 9.6EG 9.6fixed in 1.13.42025-10-06
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.13.4, the web user interface for …
- CVE-2026-34522HIGHCVSS 8.1EG 8.1fixed in 1.17.02026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability …
- CVE-2026-34523MEDIUMCVSS 5.3EG 5.3fixed in 1.17.02026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability …
- CVE-2026-34524HIGHCVSS 8.8EG 8.8fixed in 1.17.02026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, a path traversal vulnerability …
- CVE-2026-34526MEDIUMCVSS 5.0EG 5.0fixed in 1.17.02026-04-02
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to version 1.17.0, in src/endpoints/search.js, the…
- CVE-2026-44648HIGHCVSS 7.5EG 7.5fixed in 1.18.02026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session fo…
- CVE-2026-44649CRITICALCVSS 9.8EG 9.8fixed in 1.18.02026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern accepts Remote-User (Authel…
- CVE-2026-44650CRITICALCVSS 9.1EG 9.1fixed in 1.18.02026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, POST /api/extensions/delete endpoint ac…
- CVE-2026-44651MEDIUMCVSS 6.9EG 6.9fixed in 1.18.02026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, when fetch(url) throws, the code sends:…
- CVE-2026-44652MEDIUMCVSS 6.9EG 6.9fixed in 1.18.02026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, corsProxyMiddleware forwards req.params…
- CVE-2026-46372HIGHCVSS 8.5EG 8.5fixed in 1.18.02026-05-19
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern exposes /api/search/searxng…
Check whether sillytavern is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sillytavern CVEs against the assets you own.
Book a Demo →