Tag
high
advisory
SillyTavern SSRF Vulnerability in SearXNG Search Proxy via Unvalidated baseUrl
2 rules 1 TTPSillyTavern version 1.17.0 is vulnerable to server-side request forgery (SSRF) via the `/api/search/searxng` route, allowing authenticated low-privilege users to control the `baseUrl` parameter for outbound server-side fetches, potentially disclosing sensitive information from internal HTTP services or cloud metadata endpoints.
sillytavern
ssrf
github advisory
2r
1t
high
advisory
SillyTavern Path Traversal Vulnerability in Chat Endpoints
3 rules 4 TTPsA path traversal vulnerability in SillyTavern versions 1.16.0 and earlier allows an authenticated attacker to read and delete arbitrary files under their user data root by manipulating the avatar_url parameter in the `/api/chats/export` and `/api/chats/delete` endpoints.
path-traversal
web-application
sillytavern
3r
4t